1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3. Password field with autocomplete enabled
6. Private IP addresses disclosed
| Severity: | High | 
| Confidence: | Certain | 
| Host: | https://www.viglink.com | 
| Path: | /users/action/login | 
| POST /users/action/login HTTP/1.1 Host: www.viglink.com Connection: keep-alive Referer: http://www.viglink.com Content-Length: 157 Cache-Control: max-age=0 Origin: http://www.viglink.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vglnk.Referrer.p=12412; vglnk.Agent.p=9575d1 authRedirect=%2Fusers | 
| HTTP/1.1 200 OK Date: Mon, 18 Apr 2011 23:50:46 GMT Expires: Sat, 06 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: JSESSIONID=952FC9993 Content-Type: text/html;charset=UTF-8 Content-Language: en Vary: Accept-Encoding Content-Length: 5561 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive <!doctype html> <html lang="en" xmlns:og="http://ogp.me <head> <title>VigLink - Sign In</title> <meta http-equiv="Content-type" content="text/ht ...[SNIP]... <input id="email" name="email" size="30" type="text" value="2b08d"><script>alert(1)< ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://www.viglink.com | 
| Path: | /users/action/login | 
| POST /users/action/login HTTP/1.1 Host: www.viglink.com Connection: keep-alive Referer: http://www.viglink.com Content-Length: 157 Cache-Control: max-age=0 Origin: http://www.viglink.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vglnk.Referrer.p=12412; vglnk.Agent.p=9575d1 authRedirect=%2Fusers | 
| HTTP/1.1 200 OK Date: Mon, 18 Apr 2011 23:50:02 GMT Expires: Sat, 06 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: JSESSIONID=3C808A6CC Content-Type: text/html;charset=UTF-8 Content-Language: en Vary: Accept-Encoding Content-Length: 5518 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive <!doctype html> <html lang="en" xmlns:og="http://ogp.me <head> <title>VigLink - Sign In</title> <meta http-equiv="Content-type" content="text/ht ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://www.viglink.com | 
| Path: | /users/action/login | 
| POST /users/action/login HTTP/1.1 Host: www.viglink.com Connection: keep-alive Referer: http://www.viglink.com Content-Length: 157 Cache-Control: max-age=0 Origin: http://www.viglink.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vglnk.Referrer.p=12412; vglnk.Agent.p=9575d1 authRedirect=%2Fusers | 
| HTTP/1.1 200 OK Date: Mon, 18 Apr 2011 23:50:02 GMT Expires: Sat, 06 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: JSESSIONID=3C808A6CC Content-Type: text/html;charset=UTF-8 Content-Language: en Vary: Accept-Encoding Content-Length: 5518 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive <!doctype html> <html lang="en" xmlns:og="http://ogp.me <head> <title>VigLink - Sign In</title> <meta http-equiv="Content-type" content="text/ht ...[SNIP]... </h2> <form action="https://www <input type="hidden" name="authRedirect" value=""/> ...[SNIP]... </label> <input id="password" name="password" size="30" type="password"/> <button type="submit"> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Tentative | 
| Host: | https://www.viglink.com | 
| Path: | /combined.js.h898114336 | 
| GET /combined.js.h898114336 Host: www.viglink.com Connection: keep-alive Referer: https://www.viglink.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vglnk.Referrer.p=12412; vglnk.Agent.p=9575d1 | 
| HTTP/1.1 200 OK Date: Mon, 18 Apr 2011 23:50:02 GMT Cache-Control: private Expires: Thu, 15 Apr 2021 23:50:02 GMT ETag: pack898114336 X-Powered-By: pack:tag Content-Type: text/javascript;charset Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 131335 (function(f,o){function t(){if(!b.isReady){try{A ...[SNIP]... fined"};h.noConflict ...[SNIP]... .\d*)?(?:[eE][+\-]?\d+)? "]").replace(/(?:^|:|,)(? ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.viglink.com | 
| Path: | /users/action/login | 
| POST /users/action/login HTTP/1.1 Host: www.viglink.com Connection: keep-alive Referer: http://www.viglink.com Content-Length: 157 Cache-Control: max-age=0 Origin: http://www.viglink.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vglnk.Referrer.p=12412; vglnk.Agent.p=9575d1 authRedirect=%2Fusers | 
| HTTP/1.1 200 OK Date: Mon, 18 Apr 2011 23:50:02 GMT Expires: Sat, 06 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: JSESSIONID=3C808A6CC Content-Type: text/html;charset=UTF-8 Content-Language: en Vary: Accept-Encoding Content-Length: 5518 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive <!doctype html> <html lang="en" xmlns:og="http://ogp.me <head> <title>VigLink - Sign In</title> <meta http-equiv="Content-type" content="text/ht ...[SNIP]... <meta property="og:email" content="info@viglink.com"/> ...[SNIP]... <input id="email" name="email" size="30" type="text" value="" placeholder="you@example.com"/> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.viglink.com | 
| Path: | /users/action/login | 
| POST /users/action/login HTTP/1.1 Host: www.viglink.com Connection: keep-alive Referer: http://www.viglink.com Content-Length: 157 Cache-Control: max-age=0 Origin: http://www.viglink.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vglnk.Referrer.p=12412; vglnk.Agent.p=9575d1 authRedirect=%2Fusers | 
| HTTP/1.1 200 OK Date: Mon, 18 Apr 2011 23:50:02 GMT Expires: Sat, 06 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: JSESSIONID=3C808A6CC Content-Type: text/html;charset=UTF-8 Content-Language: en Vary: Accept-Encoding Content-Length: 5518 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive <!doctype html> <html lang="en" xmlns:og="http://ogp.me <head> <title>VigLink - Sign In</title> <meta http-equiv="Content-type" content="text/ht ...[SNIP]... <!-- Served by: www.viglink.com (10.245.213.194) --> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.viglink.com | 
| Path: | /users/action/login | 
| GET /robots.txt HTTP/1.0 Host: www.viglink.com | 
| HTTP/1.1 200 OK Date: Mon, 18 Apr 2011 23:50:03 GMT Expires: Sat, 06 May 1995 12:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: JSESSIONID=E9825F4C0 Accept-Ranges: bytes ETag: W/"64-1268787640000" Last-Modified: Wed, 17 Mar 2010 01:00:40 GMT Content-Type: text/plain Content-Length: 64 Vary: Accept-Encoding Connection: close # Allow all robots to browse everywhere User-agent: * Disallow: | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.viglink.com | 
| Path: | / | 
| Issued to: | *.viglink.com | 
| Issued by: | Go Daddy Secure Certification Authority | 
| Valid from: | Tue Aug 03 19:37:17 CDT 2010 | 
| Valid to: | Fri Sep 18 12:57:17 CDT 2015 | 
| Issued to: | Go Daddy Secure Certification Authority | 
| Issued by: | Go Daddy Class 2 Certification Authority | 
| Valid from: | Wed Nov 15 19:54:37 CST 2006 | 
| Valid to: | Sun Nov 15 19:54:37 CST 2026 | 
| Issued to: | Go Daddy Class 2 Certification Authority | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Tue Jun 29 12:06:20 CDT 2004 | 
| Valid to: | Sat Jun 29 12:06:20 CDT 2024 | 
| Issued to: | http://www.valicert.com/ | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Fri Jun 25 19:19:54 CDT 1999 | 
| Valid to: | Tue Jun 25 19:19:54 CDT 2019 | 
| Issued to: | http://www.valicert.com/ | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Fri Jun 25 19:19:54 CDT 1999 | 
| Valid to: | Tue Jun 25 19:19:54 CDT 2019 |