1. Cross-site scripting (reflected)
1.1. https://xchange.demandware.com/Login.jsp [invalid parameter]
1.2. https://xchange.demandware.com/Login.jsp [invalid parameter]
3. Cookie without HttpOnly flag set
4. Password field with autocomplete enabled
5. Cross-domain Referer leakage
6.1. https://xchange.demandware.com/Login.jsp
6.2. https://xchange.demandware.com/version/3.8.0.347a/js/Core.js
6.3. https://xchange.demandware.com/version/3.8.0.347a/js/lang/calendar-en.js
7.1. https://xchange.demandware.com/empty.html
7.2. https://xchange.demandware.com/servlet/CacheCheck
7.3. https://xchange.demandware.com/servlet/ObjectMetaData
7.4. https://xchange.demandware.com/servlet/XMLQuery
7.5. https://xchange.demandware.com/version/3.8.0.347a/js/Enumerations.js/1300356906030
8. Multiple content types specified
9. HTML does not specify charset
10. Content type incorrectly stated
10.1. https://xchange.demandware.com/servlet/ObjectMetaData
10.2. https://xchange.demandware.com/version/3.8.0.347a/js/Enumerations.js/1300356906030
Severity: | High |
Confidence: | Certain |
Host: | https://xchange |
Path: | /Login.jsp |
GET /Login.jsp?invalid=28a08"%3balert(1)/ Host: xchange.demandware.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 12:22:57 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Type: text/html;charset=UTF-8 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive X-Pad: avoid browser bug Content-Length: 53563 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html><head><title>Log In</title><META HTTP-EQUIV="pragma" CONTENT="no-cache"> <META HTTP-E ...[SNIP]... cerWidth: 0, paddingTop: 0, onclick: { fn: function() {document.location = "SignUp.jsp"} } }); signUpBtn.Build(getEl( } } // set error messages var invalid = "28a08";alert(1)/ if (getEl("loginHelpDiv")) getEl("loginHelpDiv") PageGlobal.showMessage // test supported browser, but warn once ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://xchange |
Path: | /Login.jsp |
GET /Login.jsp?invalid=%27%22 Host: xchange.demandware.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 12:23:00 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Type: text/html;charset=UTF-8 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive X-Pad: avoid browser bug Content-Length: 53635 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html><head><title>Log In</title><META HTTP-EQUIV="pragma" CONTENT="no-cache"> <META HTTP-E ...[SNIP]... </script>fe32f<script>alert(1)< if (getEl("loginHelpDiv")) getEl("loginHelpDiv") PageGlobal.showMessage // test supported browser, but warn once ...[SNIP]... |
Severity: | Medium |
Confidence: | Certain |
Host: | https://xchange |
Path: | / |
Issued to: | *.demandware.com |
Issued by: | Go Daddy Secure Certification Authority |
Valid from: | Fri Aug 07 08:55:46 CDT 2009 |
Valid to: | Sun Aug 07 08:11:18 CDT 2011 |
Issued to: | COMODO High Assurance Secure Server CA |
Issued by: | COMODO Certification Authority |
Valid from: | Thu Nov 30 18:00:00 CST 2006 |
Valid to: | Tue Dec 31 17:59:59 CST 2019 |
Issued to: | COMODO Certification Authority |
Issued by: | UTN - DATACorp SGC |
Valid from: | Thu Nov 30 18:00:00 CST 2006 |
Valid to: | Sat May 30 05:48:38 CDT 2020 |
Issued to: | UTN - DATACorp SGC |
Issued by: | AddTrust External CA Root |
Valid from: | Tue Jun 07 03:09:10 CDT 2005 |
Valid to: | Sat May 30 05:48:38 CDT 2020 |
Issued to: | AddTrust External CA Root |
Issued by: | AddTrust External CA Root |
Valid from: | Tue May 30 05:48:38 CDT 2000 |
Valid to: | Sat May 30 05:48:38 CDT 2020 |
Severity: | Low |
Confidence: | Firm |
Host: | https://xchange |
Path: | / |
GET / HTTP/1.1 Host: xchange.demandware.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:29:47 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Set-Cookie: JSESSIONID=5E5FE174A Content-Type: text/html;charset=UTF-8 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Length: 48441 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html><head><META HTTP-EQUIV="pragma" CONTENT="no-cache"> <META HTTP-EQUIV="cache-control ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://xchange |
Path: | /Login.jsp |
GET /Login.jsp?goto=https%3A Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:30:43 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Type: text/html;charset=UTF-8 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive X-Pad: avoid browser bug Content-Length: 53760 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html><head><title>Log In</title><META HTTP-EQUIV="pragma" CONTENT="no-cache"> <META HTTP-E ...[SNIP]... </div> <form name=loginForm action="Login" method="POST"> <input type=hidden name=logging value=""/> ...[SNIP]... <td class=fieldData><input type=password name=password id=password size=25 onkeydown='PageGlobal ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /Login.jsp |
GET /Login.jsp?goto=https%3A Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:30:43 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Type: text/html;charset=UTF-8 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive X-Pad: avoid browser bug Content-Length: 53760 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html><head><title>Log In</title><META HTTP-EQUIV="pragma" CONTENT="no-cache"> <META HTTP-E ...[SNIP]... <td><a border="0" href="https://demandware ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /Login.jsp |
GET /Login.jsp?goto=https%3A Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:30:43 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Type: text/html;charset=UTF-8 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive X-Pad: avoid browser bug Content-Length: 53760 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html><head><title>Log In</title><META HTTP-EQUIV="pragma" CONTENT="no-cache"> <META HTTP-E ...[SNIP]... </b>"; var emailFrom = "suptest@demandware.com"; if (emailFrom != "") msg += " " + Msgs.get("OR_SUBMIT_CASE ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /version/3.8.0.347a/js |
GET /version/3.8.0.347a/js Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:23:41 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Cache-Control: public,max-age=315360000 ETag: W/"1320707-1268334532000" Last-Modified: Thu, 11 Mar 2010 19:08:52 GMT Content-Type: text/javascript Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Length: 1320707 /* Copyright 2005-2008 Helpstream, Inc. All Rights Reserved. */ /* */ var CoreJS={}; function assert(b,a){}var defaultErrorHandler ...[SNIP]... <mihai_bazon@yahoo.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /version/3.8.0.347a/js |
GET /version/3.8.0.347a/js Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:23:41 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Cache-Control: public,max-age=315360000 ETag: W/"3600-1268334134000" Last-Modified: Thu, 11 Mar 2010 19:02:14 GMT Content-Type: text/javascript Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Length: 3600 // ** I18N // Calendar EN language // Author: Mihai Bazon, <mihai_bazon@yahoo.com> // Encoding: any // Distributed under the same terms as the calendar itself. // For translators: please use UTF-8 i ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /empty.html |
GET /empty.html HTTP/1.1 Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:23:56 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" ETag: W/"189-1268334132000" Last-Modified: Thu, 11 Mar 2010 19:02:12 GMT Content-Type: text/html Content-Length: 189 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Empty</title> </head> <body> </body> </html> |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /servlet/CacheCheck |
GET /servlet/CacheCheck HTTP/1.1 Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:30:49 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Cache-Control: public,max-age=315360000 Content-Type: text/html;charset=UTF-8 Content-Length: 141 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive <html><body onload="onbodyload();"> |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /servlet/ObjectMetaData |
POST /servlet/ObjectMetaData HTTP/1.1 Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange Origin: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/xml Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 Content-Length: 164 <objectMetaData><entity |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:32:22 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Length: 47 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/plain {entity: "ForumPostCustomFields", fields : {}} |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /servlet/XMLQuery |
POST /servlet/XMLQuery HTTP/1.1 Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange Origin: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/xml Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 Content-Length: 1101 <CategoryContent MaxRetrieve="10" Sort="record.lastMod ...[SNIP]... |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:24:29 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Type: text/xml;charset=UTF-8 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Length: 5282 <ArrayOfCategoryContent Duration="380 ms"><CategoryContent ID="9e01394a339a7577 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /version/3.8.0.347a/js |
GET /version/3.8.0.347a/js Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:23:41 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Cache-Control: public,max-age=315360000 Cache-Control: public,max-age=315360000 Last-Modified: Fri, 29 Apr 2011 11:22:41 GMT Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/plain Content-Length: 51364 var Enumerations = {}; Enumerations.Procedu Enumerations.Procedu ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /version/3.8.0.347a/js |
GET /version/3.8.0.347a/js Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:23:45 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Cache-Control: public,max-age=315360000 ETag: W/"175721-1268334134000" Last-Modified: Thu, 11 Mar 2010 19:02:14 GMT Content-Type: text/javascript Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Length: 175721 var tinymce={majorVersion:"3" ...[SNIP]... <base href="'+F.documentBaseURI ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://xchange |
Path: | /empty.html |
GET /empty.html HTTP/1.1 Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:23:56 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" ETag: W/"189-1268334132000" Last-Modified: Thu, 11 Mar 2010 19:02:12 GMT Content-Type: text/html Content-Length: 189 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Empty</title> </head> <body> </body> </html> |
Severity: | Information |
Confidence: | Firm |
Host: | https://xchange |
Path: | /servlet/ObjectMetaData |
POST /servlet/ObjectMetaData HTTP/1.1 Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange Origin: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/xml Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 Content-Length: 164 <objectMetaData><entity |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:32:22 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Content-Length: 47 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/plain {entity: "ForumPostCustomFields", fields : {}} |
Severity: | Information |
Confidence: | Firm |
Host: | https://xchange |
Path: | /version/3.8.0.347a/js |
GET /version/3.8.0.347a/js Host: xchange.demandware.com Connection: keep-alive Referer: https://xchange User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=203711493 |
HTTP/1.1 200 OK Date: Fri, 29 Apr 2011 11:23:41 GMT P3P: CP="ALL DSP COR CUR ADMi TAI PSA IVA HIS OUR IND STA" Cache-Control: public,max-age=315360000 Cache-Control: public,max-age=315360000 Last-Modified: Fri, 29 Apr 2011 11:22:41 GMT Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/plain Content-Length: 51364 var Enumerations = {}; Enumerations.Procedu Enumerations.Procedu ...[SNIP]... |