1. Cross-site scripting (reflected)
2. Cleartext submission of password
3. Cookie scoped to parent domain
4. Cookie without HttpOnly flag set
5. Password field with autocomplete enabled
6. Cross-domain Referer leakage
7. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security1f6b6'-alert(1)- Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230c9946 Set-Cookie: JSESSIONID=6230c9946 Date: Tue, 26 Apr 2011 21:51:16 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... <script type="text/javascript"> tweetmeme_url = 'http://www.computer tweetmeme_source = 'computerworlduknews'; tweetmeme_style = 'compact'; </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230eb99a Set-Cookie: JSESSIONID=6230eb99a Date: Tue, 26 Apr 2011 21:51:51 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... <script type="text/javascript"> tweetmeme_url = 'http://www.computer tweetmeme_source = 'computerworlduknews'; tweetmeme_style = 'compact'; </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230b3aed Set-Cookie: JSESSIONID=6230b3aed Date: Tue, 26 Apr 2011 21:50:15 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... <script type="text/javascript"> tweetmeme_url = 'http://www.computer tweetmeme_source = 'computerworlduknews'; tweetmeme_style = 'compact'; </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=623050f4d Set-Cookie: JSESSIONID=623050f4d Date: Tue, 26 Apr 2011 21:49:46 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... <script type="text/javascript"> tweetmeme_url = 'http://www.computer tweetmeme_source = 'computerworlduknews'; tweetmeme_style = 'compact'; </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230266d0 Set-Cookie: JSESSIONID=6230266d0 Date: Tue, 26 Apr 2011 21:49:09 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... </a> <form name="fbLoginForm" id="fbLoginFormID" action="/login/" method="post" class="genericForm ajaxForm" enctype="multipart/form <div id="emailFormFieldCo ...[SNIP]... <span class="inputWrapper"> <input type="password" name="password" id="passwordFieldID" class="formpassword " value="**********" onclick="if(this.value==' </span> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230266d0 Set-Cookie: JSESSIONID=6230266d0 Date: Tue, 26 Apr 2011 21:49:09 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230266d0 Set-Cookie: JSESSIONID=6230266d0 Date: Tue, 26 Apr 2011 21:49:09 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230266d0 Set-Cookie: JSESSIONID=6230266d0 Date: Tue, 26 Apr 2011 21:49:09 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... </a> <form name="fbLoginForm" id="fbLoginFormID" action="/login/" method="post" class="genericForm ajaxForm" enctype="multipart/form <div id="emailFormFieldCo ...[SNIP]... <span class="inputWrapper"> <input type="password" name="password" id="passwordFieldID" class="formpassword " value="**********" onclick="if(this.value==' </span> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230266d0 Set-Cookie: JSESSIONID=6230266d0 Date: Tue, 26 Apr 2011 21:49:09 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://w.sharethis ...[SNIP]... <li><a href="http://www.facebook ...[SNIP]... <li><a href="http://digg.com ...[SNIP]... <li><a href="http://twitter.com ...[SNIP]... <li><a href="http://www.linkedin ...[SNIP]... <p id="followTwitterConvo" ...[SNIP]... <noscript> <a href="http://ad.uk <img src="http://ad.uk </a> ...[SNIP]... <p class="articleInfo">By Ellen Messmer | <a href="http://www ...[SNIP]... Alerts team has thanked it for the information provided about an "arbitrary URL redirect vulnerability" in www.java.com. YGN published advisory information about this vulnerability both on the public <a href="http://seclists.org ...[SNIP]... YGN and Oracle, which took place over the last week, seems to have followed a far different course than the hacker group's recent interaction with McAfee, which ended last month with YGN disclosing it <a href="http://www ...[SNIP]... <p><a href="http://www ...[SNIP]... </script> <script type="text/javascript" src="http://widgets.digg ...[SNIP]... <li id="tweetArticle"><script type="text/javascript" src="http://tweetmeme.com <li id="diggArticle" class="last"><a href="http://digg.com ...[SNIP]... <noscript> <a href="http://ad.uk <img src="http://ad.uk </a> ...[SNIP]... <noscript> <a href="http://ad.uk <img src="http://ad.uk </a> ...[SNIP]... <noscript> <a href="http://ad.uk <img src="http://ad.uk </a> ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.cio.co ...[SNIP]... <li><a href="http://www.macworld ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.macvideo ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.cfoworld ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230266d0 Set-Cookie: JSESSIONID=6230266d0 Date: Tue, 26 Apr 2011 21:49:09 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://w.sharethis ...[SNIP]... </script> <script type="text/javascript" src="http://widgets.digg ...[SNIP]... <li id="tweetArticle"><script type="text/javascript" src="http://tweetmeme.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.computerw |
Path: | /news/security/3276305 |
GET /news/security/3276305 Host: www.computerworlduk.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Microsoft-IIS/6.0 Set-Cookie: JSESSIONID=6230266d0 Set-Cookie: JSESSIONID=6230266d0 Date: Tue, 26 Apr 2011 21:49:09 GMT Connection: close <!DOCTYPE html> <html> <head><script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml=" _cf_contextpath="" ...[SNIP]... <script type="text/javascript" language="javascript"> var SocialMediaUnit6 = new SocialMediaPollUnit(6,' via @Think_Print','Tweet your answer here...',123,10,7,'joao_felizardo@idg.co.uk'); </script> ...[SNIP]... |