1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
3. Cross-domain script include
4. Private IP addresses disclosed
6. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.randco.fr |
Path: | / |
GET /?p=contact1b377"><img%20src%3da Host: www.randco.fr Proxy-Connection: keep-alive Referer: http://www.randco.fr/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=112901127 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:57:27 GMT Server: Apache Content-Length: 5042 Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title></t ...[SNIP]... <img src="img/ssmenu-contact1b377\"><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.randco.fr |
Path: | / |
GET /?p=societe HTTP/1.1 Host: www.randco.fr Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=112901127 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:57:43 GMT Server: Apache Content-Length: 8688 Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Not ...[SNIP]... <link rel="stylesheet" type="text/css" href="css/stylerandco.css <script type="text/javascript" src="http://ajax <script type="text/javascript" src="http://ajax ...[SNIP]... <li id="none"><a class="transparent" title="Devis Gratuit !" ="target="_BLANK" href="http://devis.randco ...[SNIP]... <P>En 2007, notre partenariat avec <A href="http://www.nagios ...[SNIP]... <BR><IFRAME height=300 marginHeight=0 src="http://maps.google ...[SNIP]... <BR><IFRAME height=300 marginHeight=0 src="http://maps.google ...[SNIP]... <p>Notre site <a href="http://www Cabinets de conseil</a> : <a href="http://www Conseil IT</a> de l'annuaire <a href="http://www ...[SNIP]... <!-- fin div page ?--> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.randco.fr |
Path: | / |
GET /? HTTP/1.1 Host: www.randco.fr Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=112901127 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:57:48 GMT Server: Apache Content-Length: 14199 Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Ran ...[SNIP]... <link rel="stylesheet" type="text/css" href="css/stylerandco.css <script type="text/javascript" src="http://ajax <script type="text/javascript" src="http://ajax ...[SNIP]... <li id="none"><a class="transparent" title="Devis Gratuit !" ="target="_BLANK" href="http://devis.randco ...[SNIP]... <div id="actu2"> <a href="http://twitter.com <a href="http://blog.randco ...[SNIP]... <!-- fin div page ?--> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.randco.fr |
Path: | / |
GET /?p=actualites&ID=27 HTTP/1.1 Host: www.randco.fr Proxy-Connection: keep-alive Referer: http://www.randco.fr/?p User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=112901127 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:57:27 GMT Server: Apache Content-Length: 19407 Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Art ...[SNIP]... <link rel="stylesheet" type="text/css" href="css/stylerandco.css <script type="text/javascript" src="http://ajax <script type="text/javascript" src="http://ajax ...[SNIP]... <li id="none"><a class="transparent" title="Devis Gratuit !" ="target="_BLANK" href="http://devis.randco ...[SNIP]... </A>ou sur <A href="http://www.twitter ...[SNIP]... <!-- fin div page ?--> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.randco.fr |
Path: | / |
GET / HTTP/1.1 Host: www.randco.fr Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:56:59 GMT Server: Apache Content-Length: 14199 Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Ran ...[SNIP]... <link rel="stylesheet" type="text/css" href="css/stylerandco.css <script type="text/javascript" src="http://ajax <script type="text/javascript" src="http://ajax ...[SNIP]... <!-- fin div page ?--> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.randco.fr |
Path: | / |
GET /?p=actualites&ID=27 HTTP/1.1 Host: www.randco.fr Proxy-Connection: keep-alive Referer: http://www.randco.fr/?p User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=112901127 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:57:27 GMT Server: Apache Content-Length: 19407 Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Art ...[SNIP]... <CODE>Internet address is 172.31.252.31/24 MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec, </CODE> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.randco.fr |
Path: | / |
GET /robots.txt HTTP/1.0 Host: www.randco.fr |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:57:00 GMT Server: Apache Last-Modified: Fri, 09 Feb 2007 21:51:17 GMT ETag: "6817e-127-4291228c51f40" Accept-Ranges: bytes Content-Length: 295 Connection: close Content-Type: text/plain # exclude help system from robots User-agent: * Disallow: /addon-modules/ Disallow: /doc/ Disallow: /images/ # same idea here... Disallow: /Depot/ Disallow: /admin/ # but allow htdig to index our doc- ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.randco.fr |
Path: | /img/sponsors/bergame.png |
GET /img/sponsors/bergame.png HTTP/1.1 Host: www.randco.fr Proxy-Connection: keep-alive Referer: http://www.randco.fr/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 11:57:11 GMT Server: Apache Last-Modified: Mon, 26 Apr 2010 15:02:09 GMT ETag: "42cf-f44-485250f9bde40" Accept-Ranges: bytes Content-Length: 3908 Content-Type: image/png ......JFIF.....d.d.... ... ...... ...........C. ...[SNIP]... |