1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /all_sports/articles/msn |
GET /all_sportsb0206"><a>5e44f9623aa/articles/msn/greatest Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:24 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "dcd1bed9905d4f8b52d X-Runtime: 75ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 64377 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /all_sports/articles/msn |
GET /all_sports/articles/msn Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:58 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "97ff1e6db883bc8b1a3 X-Runtime: 69ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 64377 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /all_sports/articles/msn |
GET /all_sports/articles/msn Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:07:14 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "4a58fc63e41732d708c X-Runtime: 310ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 64637 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /college_football |
GET /college_footballadf19"><a>b90160f6fca/articles/msn/come_on Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:28 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "c7d1f92cd8fe11617a2 X-Runtime: 75ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 74646 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /college_football |
GET /college_football Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:39 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "31cae7f782f90b2db6b X-Runtime: 77ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 74646 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /college_football |
GET /college_football Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:59 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "692bdd77ba648fcbd37 X-Runtime: 140ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 74646 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.yardbarker.com |
Path: | /college_football |
GET /college_football Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:27 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "361138a65d0d3f82dc6 X-Runtime: 67ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 74671 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /nfl/articles/msn |
GET /nflda72b"><a>ff0234e3ef4/articles/msn/movement_to Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:29 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "f94d91bc85dd6ef92f1 X-Runtime: 66ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 122855 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yardbarker.com |
Path: | /nfl/articles/msn |
GET /nfl/articles/msn Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:58 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "8ebc44f6273a466b8c0 X-Runtime: 66ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 122855 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.yardbarker.com |
Path: | /nfl/articles/msn |
GET /nfl/articles/msn Host: www.yardbarker.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.8.35 Date: Thu, 24 Mar 2011 13:06:28 GMT Content-Type: text/html; charset=utf-8 Connection: close Status: 200 OK P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR" ETag: "2dcf6d9d60bb91464de X-Runtime: 81ms Cache-Control: private, max-age=0, must-revalidate Set-Cookie: _Yardbarker_session Content-Length: 122880 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <meta property="og:url" content="http://www ...[SNIP]... |