1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | https://verify.authorize |
Path: | /anetseal/ |
GET /anetseal/?pid=3de2b6f5 Host: verify.authorize.net Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:17:23 GMT Server: Microsoft-IIS/6.0 P3P: CP="NOI NID NAV" X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Cache-Control: no-cache Pragma: no-cache Expires: -1 Content-Type: text/html; charset=utf-8 Content-Length: 5955 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" > <html> <head> <title>Authorize.Net Verified Merchant Seal</title> <meta name="GENERATOR" Content="Microsoft Visual St ...[SNIP]... <a href= https://www.clone-systems ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://verify.authorize |
Path: | /anetseal/ |
GET /anetseal/?pid=3de2b6f5 Host: verify.authorize.net Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:16:25 GMT Server: Microsoft-IIS/6.0 P3P: CP="NOI NID NAV" X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Cache-Control: no-cache Pragma: no-cache Expires: -1 Content-Type: text/html; charset=utf-8 Content-Length: 5797 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" > <html> <head> <title>Authorize.Net Verified Merchant Seal</title> <meta name="GENERATOR" Content="Microsoft Visual St ...[SNIP]... <td class="MainHeaderFont"> <a href= https://www.clone-systems ...[SNIP]... <p> You can be confident in knowing that <a href= https://www.clone-systems ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://verify.authorize |
Path: | /anetseal/ |
GET /robots.txt HTTP/1.0 Host: verify.authorize.net |
HTTP/1.1 200 OK Content-Length: 28 Content-Type: text/plain Last-Modified: Wed, 21 Feb 2007 20:25:16 GMT Accept-Ranges: bytes ETag: "09eb465f655c71:85f" Server: Microsoft-IIS/6.0 P3P: CP="NOI NID NAV" X-Powered-By: ASP.NET Date: Sat, 07 May 2011 01:16:27 GMT Connection: close User-agent: * Disallow: / |
Severity: | Information |
Confidence: | Firm |
Host: | https://verify.authorize |
Path: | /anetseal/images |
GET /anetseal/images Host: verify.authorize.net Connection: keep-alive Referer: https://www.clone-systems User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Length: 2894 Content-Type: image/gif Last-Modified: Fri, 26 Mar 2010 17:33:22 GMT Accept-Ranges: bytes ETag: "0dd746eacdca1:a13" Server: Microsoft-IIS/6.0 P3P: CP="NOI NID NAV" X-Powered-By: ASP.NET Date: Sat, 07 May 2011 00:56:38 GMT .PNG . ...IHDR...Z...H.....v...... .IDATx...?.+G...G.G...pK. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://verify.authorize |
Path: | / |
Issued to: | *.authorize.net |
Issued by: | Entrust Certification Authority - L1C |
Valid from: | Wed Mar 31 12:04:00 CDT 2010 |
Valid to: | Fri Mar 30 12:33:57 CDT 2012 |
Issued to: | Entrust Certification Authority - L1C |
Issued by: | Entrust.net Certification Authority (2048) |
Valid from: | Thu Dec 10 14:43:54 CST 2009 |
Valid to: | Tue Dec 10 15:13:54 CST 2019 |
Issued to: | Entrust.net Certification Authority (2048) |
Issued by: | Entrust.net Certification Authority (2048) |
Valid from: | Fri Dec 24 11:50:51 CST 1999 |
Valid to: | Tue Jul 24 09:15:12 CDT 2029 |