1. Cross-site scripting (reflected)
1.1. http://compudyne.net/about/index.php [name of an arbitrarily supplied request parameter]
1.2. http://compudyne.net/about/index.php [name of an arbitrarily supplied request parameter]
1.3. http://compudyne.net/about/index.php [page parameter]
1.4. http://compudyne.net/about/index.php [page parameter]
1.5. http://compudyne.net/about/press.php [name of an arbitrarily supplied request parameter]
1.6. http://compudyne.net/about/press.php [page parameter]
1.7. http://compudyne.net/about/print.php [page parameter]
1.8. http://compudyne.net/contact/index.php [name of an arbitrarily supplied request parameter]
1.9. http://compudyne.net/contact/index.php [name of an arbitrarily supplied request parameter]
1.10. http://compudyne.net/contact/index.php [page parameter]
1.11. http://compudyne.net/contact/index.php [page parameter]
1.12. http://compudyne.net/contact/print.php [page parameter]
1.15. http://compudyne.net/products-services/index.php [page parameter]
1.16. http://compudyne.net/products-services/index.php [page parameter]
1.17. http://compudyne.net/products-services/print.php [page parameter]
1.18. http://init.zopim.com/register [mID parameter]
1.19. http://widgets.digg.com/buttons/count [url parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /about/index.php |
GET /about/index.php?page Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:07:37 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 3861 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <title> Affiliations-Accreditat/71d9c</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /about/index.php |
GET /about/index.php?page Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:07:31 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 3849 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <a href="print.php?page ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /about/index.php |
GET /about/index.php?page Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:06:24 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 3861 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <title> Affiliations-Accredi </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /about/index.php |
GET /about/index.php?page Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:06:18 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 3845 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <a href="print.php?page ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /about/press.php |
GET /about/press.php?page=5 Host: compudyne.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:14:12 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Length: 2281 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="content-type" content="text/html <meta name="Keywords" content="Compudyne, Duluth, ...[SNIP]... <title> 5-28-09ChrisA-C/8820d</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /about/press.php |
GET /about/press.php?page=5 Host: compudyne.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:14:07 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Length: 2278 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="content-type" content="text/html <meta name="Keywords" content="Compudyne, Duluth, ...[SNIP]... <title> 5-28-09ChrisA-Cherid7eb3</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /about/print.php |
GET /about/print.php?page=9fc1f</title><script Host: compudyne.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:14:03 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Length: 2898 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="content-type" content="text/html <meta name="Keywords" content="Compudyne, Duluth, ...[SNIP]... <title> 9fc1f</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /contact/index.php |
GET /contact/index.php?page=E Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:07:31 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4449 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <a href="print.php?page=E/3f5e2\"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /contact/index.php |
GET /contact/index.php?page=E Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:07:37 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4461 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <title> E/63d5d</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /contact/index.php |
GET /contact/index.php?page Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:06:18 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4445 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <a href="print.php?page ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /contact/index.php |
GET /contact/index.php?page Host: compudyne.net Proxy-Connection: keep-alive Referer: http://compudyne.net User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:06:24 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4461 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <title> Emaila347e</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /contact/print.php |
GET /contact/print.php?page=54dfa</title><script Host: compudyne.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:13:46 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Length: 2875 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="content-type" content="text/html <meta name="Keywords" content="Compudyne, Duluth, ...[SNIP]... <title> 54dfa</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /products-services/index |
GET /products-services/index Host: compudyne.net Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 20:16:00 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4708 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <title> EDGE-Anti-/3c8ea</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /products-services/index |
GET /products-services/index Host: compudyne.net Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 20:15:54 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4692 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <a href="print.php?page=EDGE ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /products-services/index |
GET /products-services/index Host: compudyne.net Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 20:15:12 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4704 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <title> EDGE-Anti-Spam1226d</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /products-services/index |
GET /products-services/index Host: compudyne.net Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 20:15:05 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Type: text/html X-Pad: avoid browser bug Content-Length: 4688 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta htt ...[SNIP]... <a href="print.php?page=EDGE ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://compudyne.net |
Path: | /products-services/print |
GET /products-services/print Host: compudyne.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Thu, 21 Apr 2011 21:13:29 GMT Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch X-Powered-By: PHP/5.2.6-2ubuntu4.2 Vary: Accept-Encoding Content-Length: 2938 Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="content-type" content="text/html <meta name="Keywords" content="Compudyne, Duluth, ...[SNIP]... <title> 17679</title><script </title> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://init.zopim.com |
Path: | /register |
GET /register?ref=&url=http Host: init.zopim.com Proxy-Connection: keep-alive Referer: http://zopim.com/swf Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: nginx Date: Thu, 21 Apr 2011 21:13:22 GMT Connection: keep-alive Content-Length: 976 {"status": "offline", "__status": "ok", "name": "Visitor 267278572", "settings": {"chatbutton": {"position": "br", "theme": "bar", "useFavicon": false}, "greetings": {"away": {"window": "If you leave ...[SNIP]... "Leave a message"}, "online": {"window": "Leave a question or comment and our agents will try to attend to you shortly.", "bar": "Click here to chat!"}}}, "machineID": "gLAMf6t1oQdRZ9pJbWZ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://widgets.digg.com |
Path: | /buttons/count |
GET /buttons/count?url=http Host: widgets.digg.com Proxy-Connection: keep-alive Referer: http://xss.cx/examples User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Age: 0 Date: Thu, 21 Apr 2011 21:09:16 GMT Via: NS-CACHE: 100 Etag: "6455c0cc577d0689931 Content-Length: 170 Server: TornadoServer/0.1 Content-Type: application/json Accept-Ranges: bytes Cache-Control: private, max-age=599 Expires: Thu, 21 Apr 2011 21:19:15 GMT X-CDN: Cotendo Connection: Keep-Alive __DBW.collectDiggs({"url" |