Loading HuntDB...

Mixed Active content issue on https://www.lyst.com

Low
L
Lyst
Submitted None

Team Summary

Official summary from Lyst

An erroneous conditional comment for Internet Explorer browsers lower than version 9 was causing an attempted load of an insecure, non-existent JavaScript file over certain HTTPS requests from www.lyst.com. Although the targetted browser sessions were very low in number the request could still technically be hijacked. The comment has now been removed and the page no longer serves this request.

Reported by mrnull1337

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles