Would like to add to the list that possible attack is given for open social urls as well:
Total impact: 22
Affected tags: xss, csrf, sqli, id, lfi
Variable: REQUEST.request | Value: {\"context\":{\"country\":\"US\",\"language\":\"en\",\"view\":\"default\",\"container\":\"partuza\"},\"gadgets\":[{\"url\":\"http:\\/\\/jukebox.mentez.com\\/hi5\\/jukebox.xml\",\"moduleId\":\"1\"}]}
Impact: 11 | Tags: xss, csrf, sqli, id, lfi
Description: Detects self-executing JavaScript functions | Tags: xss, csrf | ID: 8
Description: Detects classic SQL injection probings 2/2 | Tags: sqli, id, lfi | ID: 43
Variable: POST.request | Value: {\"context\":{\"country\":\"US\",\"language\":\"en\",\"view\":\"default\",\"container\":\"partuza\"},\"gadgets\":[{\"url\":\"http:\\/\\/jukebox.mentez.com\\/hi5\\/jukebox.xml\",\"moduleId\":\"1\"}]}
Impact: 11 | Tags: xss, csrf, sqli, id, lfi
Description: Detects self-executing JavaScript functions | Tags: xss, csrf | ID: 8
Description: Detects classic SQL injection probings 2/2 | Tags: sqli, id, lfi | ID: 43