1. Cross-site scripting (reflected)
1.1. http://www.ezflexplan.com/navigation/frameset.asp [content parameter]
1.2. http://www.ezflexplan.com/navigation/frameset.asp [email parameter]
1.3. http://www.ezflexplan.com/navigation/frameset.asp [id parameter]
1.4. http://www.ezflexplan.com/navigation/menu.asp [id parameter]
2. Cookie without HttpOnly flag set
2.1. http://www.ezflexplan.com/lbmc/
2.2. http://www.ezflexplan.com/navigation/menu.asp
3. HTML does not specify charset
3.1. http://www.ezflexplan.com/ContentPages/employers.html
3.2. http://www.ezflexplan.com/ContentPages/er_admintls.html
3.3. http://www.ezflexplan.com/ContentPages/er_enrllmnttools.html
3.4. http://www.ezflexplan.com/ContentPages/er_htsuap.html
3.5. http://www.ezflexplan.com/ContentPages/nav_employers.html
3.6. http://www.ezflexplan.com/navigation/frameset.asp
3.7. http://www.ezflexplan.com/navigation/menu.asp
Severity: | High |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /navigation/frameset.asp |
GET /navigation/frameset.asp Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:44:43 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 962 Content-Type: text/html Cache-control: private <html> <head> <title>EzFlexPlan</title> <meta name="GENERATOR" content="Microsoft FrontPage 4.0"> <meta name="ProgId" content="FrontPage.Editor </head> <frameset border="0" fr ...[SNIP]... <frame name="leftnav" src="/ContentPages/nav_4e5ba"><script>alert(1)< scrolling="auto" frameborder="no"> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /navigation/frameset.asp |
GET /navigation/frameset.asp Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:44:42 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 866 Content-Type: text/html Cache-control: private <html> <head> <title>EzFlexPlan</title> <meta name="GENERATOR" content="Microsoft FrontPage 4.0"> <meta name="ProgId" content="FrontPage.Editor </head> <frameset border="0" fr ...[SNIP]... <frame name src="/navigation/menu.asp marginwidth="0" marginheight="0" scrolling="no" frameborder="no" style="text-align: Left"> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /navigation/frameset.asp |
GET /navigation/frameset.asp Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:44:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 892 Content-Type: text/html Cache-control: private <html> <head> <title>EzFlexPlan</title> <meta name="GENERATOR" content="Microsoft FrontPage 4.0"> <meta name="ProgId" content="FrontPage.Editor </head> <frameset border="0" fr ...[SNIP]... <frame name src="/navigation/menu.asp marginwidth="0" marginheight="0" scrolling="no" frameborder="no" style="text-align: Left"> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /navigation/menu.asp |
GET /navigation/menu.asp?id Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:44:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 3118 Content-Type: text/html Cache-control: private <html> <head> <title>EzFlexPlan Menu</title> <script LANGUAGE="JavaScript"> //HoverCraft MouseOver Script if (document.images) { var ImageDirectory = "../ ...[SNIP]... <a href="/navigation/contact onclick="parent.frames[1] target="mainbody" onmouseover="HoverCraft( onmou ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ezflexplan.com |
Path: | /lbmc/ |
GET /lbmc/ HTTP/1.1 Host: www.ezflexplan.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:36:21 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 2793 Content-Type: text/html Set-Cookie: ASPSESSIONIDCQSRSARR Cache-control: private <html> <head> <meta name="ProgId" content="FrontPage.Editor <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <script LANGUAGE="javascript"> <!-- var aIm ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ezflexplan.com |
Path: | /navigation/menu.asp |
GET /navigation/menu.asp?id Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 11:23:53 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 3032 Content-Type: text/html Set-Cookie: ASPSESSIONIDCQSRSARR Cache-control: private <html> <head> <title>EzFlexPlan Menu</title> <script LANGUAGE="JavaScript"> //HoverCraft MouseOver Script if (document.images) { var ImageDirectory = "../ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /ContentPages/employers |
GET /ContentPages/employers Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Content-Length: 6158 Content-Type: text/html Last-Modified: Thu, 11 Nov 2010 19:01:35 GMT Accept-Ranges: bytes ETag: "8e385edcd281cb1:1678" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 07 May 2011 01:44:37 GMT <html> <head> <link rel="stylesheet" href="er_content.css" type="text/css"> <meta http-equiv="Content <title>What is a Flexible Spending Account?</title> <script lang ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /ContentPages/er_admintls |
GET /ContentPages/er_admintls Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Content-Length: 2942 Content-Type: text/html Last-Modified: Thu, 07 Feb 2002 18:05:46 GMT Accept-Ranges: bytes ETag: "0f9b7102b0c11:1678" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 07 May 2011 01:45:13 GMT <html> <head> <title>Administrative Tools for Employers</title> <style> <!-- a:link { color: #6699cc } a:visited { color: #999999 } a:hover { color: #cc9900 } p { fo ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /ContentPages/er |
GET /ContentPages/er Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Content-Length: 2547 Content-Type: text/html Last-Modified: Fri, 28 Jan 2011 15:15:02 GMT Accept-Ranges: bytes ETag: "26b0aa22febecb1:1678" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 07 May 2011 01:45:19 GMT <html> <head> <link rel="stylesheet" href="er_content.css" type="text/css"> <title>Enrollment Tools</title> </head> <body bgcolor="#FFFFFF" leftmargin="0" topmargin="0"> <table cellspacing ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /ContentPages/er_htsuap |
GET /ContentPages/er_htsuap Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Content-Length: 5215 Content-Type: text/html Last-Modified: Tue, 03 Apr 2007 16:22:32 GMT Accept-Ranges: bytes ETag: "f81dd447c76c71:1678" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 07 May 2011 01:45:08 GMT <html> <head> <link rel="stylesheet" href="er_content.css" type="text/css"> <title>How to Set-Up a Plan</title> <script language="JavaScript" fptype="dynamicanimation" <!-- function dynAnimat ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /ContentPages/nav |
GET /ContentPages/nav Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Content-Length: 4111 Content-Type: text/html Last-Modified: Wed, 20 Nov 2002 18:50:32 GMT Accept-Ranges: bytes ETag: "08cd7b3c590c21:1678" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 07 May 2011 01:44:39 GMT <html> <head> <title>Employer Menu</title> <base target="mainbody"> <meta name="ProgId" content="FrontPage.Editor <meta name="GENERATOR" content="Microsoft FrontPage 5.0"> <SCRIPT L ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /navigation/frameset.asp |
GET /navigation/frameset.asp Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:44:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 814 Content-Type: text/html Cache-control: private <html> <head> <title>EzFlexPlan</title> <meta name="GENERATOR" content="Microsoft FrontPage 4.0"> <meta name="ProgId" content="FrontPage.Editor </head> <frameset border="0" fr ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ezflexplan.com |
Path: | /navigation/menu.asp |
GET /navigation/menu.asp?id Host: www.ezflexplan.com Proxy-Connection: keep-alive Referer: http://www.ezflexplan.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDCQSRSARR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:44:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 3032 Content-Type: text/html Cache-control: private <html> <head> <title>EzFlexPlan Menu</title> <script LANGUAGE="JavaScript"> //HoverCraft MouseOver Script if (document.images) { var ImageDirectory = "../ ...[SNIP]... |