1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3.1. http://www.nist.gov/search-results.cfm
3.2. http://www.nist.gov/srd/onlinelist.htm
4. Cross-domain Referer leakage
5. Cross-domain script include
6.1. http://www.nist.gov/search-results.cfm
6.2. http://www.nist.gov/srd/onlinelist.htm
7. Content type incorrectly stated
7.1. http://www.nist.gov/favicon.ico
7.2. http://www.nist.gov/style/web_fonts/functionpro_medium_macroman/FunctionPro-Medium-webfont.woff
Severity: | Low |
Confidence: | Certain |
Host: | http://www.nist.gov |
Path: | /cgi-bin/exit_nist.cgi |
GET /cgi-bin/exit_nist.cgi HTTP/1.1 Host: www.nist.gov Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: fsr.s={"v":1,"rid": Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 12:39:42 GMT Server: Apache NIST: g3 Connection: close Content-Type: text/html; charset=ISO-8859-1 Content-Length: 535 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org < ...[SNIP]... <!--http://www.google.com ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.nist.gov |
Path: | /search-results.cfm |
GET /search-results.cfm?q=xss Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://www.nist.gov/srd User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:13 GMT Server: Apache Set-Cookie: CFID=17042990;path=/ Set-Cookie: CFTOKEN=54636047;path=/ Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT NIST: g3 Content-Type: text/html; charset=iso-8859-1 Content-Length: 18308 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nist.gov |
Path: | /search-results.cfm |
GET /search-results.cfm?q=xss Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://www.nist.gov/srd User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:13 GMT Server: Apache Set-Cookie: CFID=17042990;path=/ Set-Cookie: CFTOKEN=54636047;path=/ Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT NIST: g3 Content-Type: text/html; charset=iso-8859-1 Content-Length: 18308 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <br /> <form method="post" action="https://service ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nist.gov |
Path: | /srd/onlinelist.htm |
GET /srd/onlinelist.htm HTTP/1.1 Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://data.osbm.state.nc User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:05 GMT Server: Apache NIST: g3 Content-Type: text/html; charset=UTF-8 Content-Length: 13113 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <!-- Con ...[SNIP]... <div class="social20Wrapper"> <form method="post" action="https://service <input value="http://www.nist ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nist.gov |
Path: | /search-results.cfm |
GET /search-results.cfm?q=xss Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://www.nist.gov/srd User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:13 GMT Server: Apache Set-Cookie: CFID=17042990;path=/ Set-Cookie: CFTOKEN=54636047;path=/ Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT NIST: g3 Content-Type: text/html; charset=iso-8859-1 Content-Length: 18308 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.time.gov ...[SNIP]... </a> / <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nist.gov |
Path: | /srd/onlinelist.htm |
GET /srd/onlinelist.htm HTTP/1.1 Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://data.osbm.state.nc User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:05 GMT Server: Apache NIST: g3 Content-Type: text/html; charset=UTF-8 Content-Length: 13113 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <!-- Con ...[SNIP]... </title> <script language="JavaScript" src="http://ajax ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nist.gov |
Path: | /search-results.cfm |
GET /search-results.cfm?q=xss Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://www.nist.gov/srd User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:13 GMT Server: Apache Set-Cookie: CFID=17042990;path=/ Set-Cookie: CFTOKEN=54636047;path=/ Last-Modified: Tue, 4 Jan 2011 22:32:06 GMT NIST: g3 Content-Type: text/html; charset=iso-8859-1 Content-Length: 18308 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <a href="mailto:DO-webmaster@nist.gov" class="bold"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.nist.gov |
Path: | /srd/onlinelist.htm |
GET /srd/onlinelist.htm HTTP/1.1 Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://data.osbm.state.nc User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:05 GMT Server: Apache NIST: g3 Content-Type: text/html; charset=UTF-8 Content-Length: 13113 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <!-- Con ...[SNIP]... <a href="mailto:inquiries@nist.gov"> ...[SNIP]... <a href="mailto:DO-webmaster@nist.gov">DO-webmaster@nist.gov</a> ...[SNIP]... <a href="mailto:inquiries@nist.gov">inquiries@nist.gov</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.nist.gov |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.nist.gov Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:13 GMT Server: Apache Last-Modified: Thu, 30 Sep 2010 13:17:01 GMT ETag: "3568017-13e-49179e4 Accept-Ranges: bytes Content-Length: 318 NIST: g3 Content-Type: text/plain ..............(.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.nist.gov |
Path: | /style/web_fonts |
GET /style/web_fonts Host: www.nist.gov Proxy-Connection: keep-alive Referer: http://www.nist.gov/srd User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 30 Apr 2011 01:00:08 GMT Server: Apache Last-Modified: Mon, 09 Aug 2010 19:57:20 GMT ETag: "cfc91e-7e34-48d696c Accept-Ranges: bytes Content-Length: 32308 NIST: g3 Content-Type: text/plain wOFF......~4.......0..... ...[SNIP]... |