1. Cross-site scripting (reflected)
2.1. http://speakersbureau.simonandschuster.biz/CFIDE/scripts/cfform.js
2.2. http://speakersbureau.simonandschuster.biz/speakersbureau/speaker_bureau_home.cfm
2.3. http://speakersbureau.simonandschuster.biz/speakersbureau/speaker_bureau_requestForm.cfm
Severity: | High |
Confidence: | Certain |
Host: | http://speakersbureau |
Path: | /speakersbureau/speaker |
GET /speakersbureau/speaker Host: speakersbureau.simon Proxy-Connection: keep-alive Referer: http://speakersbureau User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=446209786; CFTOKEN=36742584; s_cc=true; s_sq=%5B%5BB%5D%5D |
HTTP/1.1 200 OK Connection: close Date: Thu, 28 Apr 2011 18:33:37 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Type: text/html; charset=UTF-8 ...[SNIP]... <form name="sb_request" action="/speakersbureau ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://speakersbureau |
Path: | /CFIDE/scripts/cfform.js |
GET /CFIDE/scripts/cfform.js HTTP/1.1 Host: speakersbureau.simon Proxy-Connection: keep-alive Referer: http://speakersbureau User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=446209786; CFTOKEN=36742584; s_cc=true; s_sq=%5B%5BB%5D%5D |
HTTP/1.1 200 OK Content-Length: 21329 Content-Type: application/x-javascript Content-Location: http://speakersbureau Last-Modified: Fri, 09 Sep 2005 21:01:08 GMT Accept-Ranges: bytes ETag: "042769981b5c51:4b6" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Thu, 28 Apr 2011 18:27:50 GMT /* * Copyright (c) 1995-2005 Macromedia, Inc. All rights reserved. */ // ColdFusion JavaScript functions for cfform client-side validation var _CF_error_messages = new Array(); var _CF_error_fi ...[SNIP]... -9]{4}$/, required); } /** * validate that the value is formatted as an email address correctly * * this regex matches the majoriity of all email address. * example matches. * Matches: [rick.jones@unit.army.mil], [john_doe@foobar.com], [foo99@foo.co.uk] * Non-Matches: [find_the_mistake.@foo.org], [.prefix.@some.net] * * _CF_checkURL mailto uses this same email regex - keep in sync. */ function _CF_checkEmail(object { //trim whitespace before we validate object_value = object_value ...[SNIP]... m/index.cfm/userid/1/name * ftp://www.mm.com/ * ftp://uname:pass@www.mm.com/ * mailto:email@address.com * news:rec.gardening * news:rec.gardening * http://a/ * file://ftp.yoyodyne.com * Non-Matches: www.yahoo.com * http:www.mm.co ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://speakersbureau |
Path: | /speakersbureau/speaker |
GET /speakersbureau/speaker Host: speakersbureau.simon Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Connection: close Date: Thu, 28 Apr 2011 18:30:03 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Type: text/html; charset=UTF-8 ...[SNIP]... <a href="mailto:info@simonspeakers.com?subject=Simon and Schuster Speakers Bureau" title="Contact Us"> ...[SNIP]... <a href="mailto:info@simonspeakers.com?subject=Simon and Schuster Speakers Bureau"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://speakersbureau |
Path: | /speakersbureau/speaker |
GET /speakersbureau/speaker Host: speakersbureau.simon Proxy-Connection: keep-alive Referer: http://speakersbureau User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=446209786; CFTOKEN=36742584; s_cc=true; s_sq=%5B%5BB%5D%5D |
HTTP/1.1 200 OK Connection: close Date: Thu, 28 Apr 2011 18:33:35 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Type: text/html; charset=UTF-8 ...[SNIP]... <a href="mailto:info@simonspeakers.com?subject=Simon and Schuster Speakers Bureau" title="Contact Us"> ...[SNIP]... <a href="mailto:info@simonspeakers.com?subject=Simon and Schuster Speakers Bureau"> ...[SNIP]... |