1. Cross-site scripting (reflected)
1.1. http://www.magellangps.com/ [name of an arbitrarily supplied request parameter]
1.2. http://www.magellangps.com/s.nl [name of an arbitrarily supplied request parameter]
2. Cookie without HttpOnly flag set
3. Cross-domain Referer leakage
4. Cross-domain script include
4.1. http://www.magellangps.com/
4.2. http://www.magellangps.com/Products/eXploristseries
4.3. http://www.magellangps.com/s.nl
5.1. http://www.magellangps.com/lp/eXploristfamily/css/styles.css
5.2. http://www.magellangps.com/lp/eXploristfamily/js/main.js
5.3. http://www.magellangps.com/site/js/general-scripts.js
Severity: | High |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | / |
GET /?bb4e2%2527style%253d Host: www.magellangps.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:39:52 GMT Server: Apache Cache-Control: No-Cache,no-store Pragma: No-Cache Expires: 0 NS_RTIMER_COMPOSITE: 1673890758:73686F702 Set-Cookie: JSESSIONID=yLNYN37LT Set-Cookie: NLVisitorId=rcHW8655 Set-Cookie: NLShopperId=rcHW8655 Set-Cookie: NS_VER=2011.1.0; domain=www.magellangps X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/html; charset=utf-8 Content-Length: 77203 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title> ...[SNIP]... <input type='hidden' name='referer' value='http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | /s.nl |
GET /s.nl?sc=3&custcol_celigo Host: www.magellangps.com Proxy-Connection: keep-alive Referer: http://www.magellangps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=Q0VpN37HL |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:49:29 GMT Server: Apache Cache-Control: No-Cache,no-store Pragma: No-Cache Expires: 0 NS_RTIMER_COMPOSITE: 684099100:73686F702D X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/html; charset=utf-8 Content-Length: 86971 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title> ...[SNIP]... <input type='hidden' name='referer' value='http://www ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.magellangps |
Path: | / |
GET / HTTP/1.1 Host: www.magellangps.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:39:21 GMT Server: Apache Cache-Control: No-Cache,no-store Pragma: No-Cache Expires: 0 NS_RTIMER_COMPOSITE: 683260212:73686F702D Set-Cookie: JSESSIONID=MX8nN37Jh Set-Cookie: NLVisitorId=rcHW8655 Set-Cookie: NLShopperId=rcHW8655 Set-Cookie: NS_VER=2011.1.0; domain=www.magellangps X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/html; charset=utf-8 Content-Length: 77084 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | /s.nl |
GET /s.nl?sc=3&whence= Host: www.magellangps.com Proxy-Connection: keep-alive Referer: http://www.magellangps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=Q0VpN37HL |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:40:27 GMT Server: Apache Cache-Control: No-Cache,no-store Pragma: No-Cache Expires: 0 NS_RTIMER_COMPOSITE: -1577135949:73686F70 X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/html; charset=utf-8 Content-Length: 53685 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title> ...[SNIP]... </style> <script type="text/javascript" src="https://ajax ...[SNIP]... <li><a href='https://checkout ...[SNIP]... <li><a href="https://forms ...[SNIP]... <li><a href="https://forms ...[SNIP]... <li><a href="https://forms ...[SNIP]... <li class="eng"><a href="https://forms ...[SNIP]... <li class="ita invisible"><a href="https://forms ...[SNIP]... <li class="spa invisible"><a href="https://forms ...[SNIP]... <li class="fra invisible"><a href="https://forms ...[SNIP]... <li class="ger invisible"><a href="https://forms ...[SNIP]... <li class="social"><a id="face" href="http://facebook.com ...[SNIP]... <li class="social"><a id="twit" href="http://twitter.com ...[SNIP]... <li class="social"><a id="you" href="http://www.youtube ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="https://api <script language="javascript" type="text/javascript" src="https://api ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | / |
GET / HTTP/1.1 Host: www.magellangps.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:39:21 GMT Server: Apache Cache-Control: No-Cache,no-store Pragma: No-Cache Expires: 0 NS_RTIMER_COMPOSITE: 683260212:73686F702D Set-Cookie: JSESSIONID=MX8nN37Jh Set-Cookie: NLVisitorId=rcHW8655 Set-Cookie: NLShopperId=rcHW8655 Set-Cookie: NS_VER=2011.1.0; domain=www.magellangps X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/html; charset=utf-8 Content-Length: 77084 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title> ...[SNIP]... </style> <script type="text/javascript" src="https://ajax ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="https://api <script language="javascript" type="text/javascript" src="https://api ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | /Products/eXploristseries |
GET /Products/eXploristseries HTTP/1.1 Host: www.magellangps.com Proxy-Connection: keep-alive Referer: http://www.magellangps User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=Q0VpN37HL |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:40:13 GMT Server: Apache Expires: 0 Last-Modified: Tue, 26 Apr 2011 21:40:11 GMT NS_RTIMER_COMPOSITE: 684041816:73686F702D X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/html; charset=utf-8 Content-Length: 86023 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title> ...[SNIP]... </script> <script language="JavaScript" src="http://content ...[SNIP]... </style> <script type="text/javascript" src="https://ajax ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="https://api <script language="javascript" type="text/javascript" src="https://api ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | /s.nl |
GET /s.nl?sc=3&whence= Host: www.magellangps.com Proxy-Connection: keep-alive Referer: http://www.magellangps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=Q0VpN37HL |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:40:27 GMT Server: Apache Cache-Control: No-Cache,no-store Pragma: No-Cache Expires: 0 NS_RTIMER_COMPOSITE: -1577135949:73686F70 X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/html; charset=utf-8 Content-Length: 53685 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title> ...[SNIP]... </style> <script type="text/javascript" src="https://ajax ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="https://api <script language="javascript" type="text/javascript" src="https://api ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | /lp/eXploristfamily/css |
GET /lp/eXploristfamily/css Host: www.magellangps.com Proxy-Connection: keep-alive Referer: http://www.magellangps User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=Q0VpN37HL |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:39:38 GMT Server: Apache Cache-Control: max-age=604800 Content-Disposition: inline;filename="styles NS_RTIMER_COMPOSITE: -1241495335:73686F70 NLCacheNote: FromMediaCache=T X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/css; charset=UTF-8 Content-Length: 13045 @charset "utf-8"; /* Magellan eXplorist CSS Title: Default CSS Author: Pasquale Scerbo (pasquale@waveactive.com || pasquale@leftlanecreative Date: March 2010 */ /*----------------- CSS NORMALIZER -----------------*/ /* - cancels default styles applied to page elements - adjusts default elements between browsers to same baseline ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | /lp/eXploristfamily/js |
GET /lp/eXploristfamily/js Host: www.magellangps.com Proxy-Connection: keep-alive Referer: http://www.magellangps User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=Q0VpN37HL |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:39:39 GMT Server: Apache Cache-Control: max-age=604800 Content-Disposition: inline;filename="main.js" NS_RTIMER_COMPOSITE: -353693915:73686F702 NLCacheNote: FromMediaCache=T X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: text/javascript; charset=UTF-8 Content-Length: 3242 /* Magellan eXplorist JavaScript File */ /* Author: Pasquale Scerbo (pasquale@waveactive.com || pasquale@leftlanecreative March 2010 */ /* Must be used with jQuery Library */ $(document).ready /************************ // jQuery Tooltip (Screen Three) /***************** ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | /site/js/general-scripts |
GET /site/js/general-scripts Host: www.magellangps.com Proxy-Connection: keep-alive Referer: http://www.magellangps User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=Q0VpN37HL |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:39:27 GMT Server: Apache Cache-Control: max-age=604800 Content-Disposition: inline;filename="general NS_RTIMER_COMPOSITE: 348391173:73686F702D NLCacheNote: FromMediaCache=T X-Powered-By: Servlet/2.5 JSP/2.1 P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Content-Type: application/x-javascript; charset=UTF-8 Content-Length: 7430 /* * hoverIntent r5 // 2007.03.27 // jQuery 1.1.2+ * <http://cherne.net/brian * * @param f onMouseOver function || An object with configuration options * @pa ...[SNIP]... <brian@cherne.net> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.magellangps |
Path: | / |
GET /robots.txt HTTP/1.0 Host: www.magellangps.com |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 21:39:24 GMT Server: Apache Content-Length: 103 Last-Modified: Sat, 23 Apr 2011 00:28:30 GMT NS_RTIMER_COMPOSITE: 1571838000:73686F702 X-Powered-By: Servlet/2.5 JSP/2.1 Set-Cookie: NS_VER=2011.1.0; domain=www.magellangps P3P: CP="CAO PSAa OUR BUS PUR" Vary: User-Agent Keep-Alive: timeout=10, max=833 Connection: Keep-Alive Content-Type: text/plain # Allow all robots to spider everything by disallowing nothing User-agent: * Crawl-Delay: 20 Disallow: |