2. SQL statement in request parameter
3.1. http://app.businessweek.com/UserComments/combo_review
3.2. http://app.businessweek.com/UserComments/static/admin.css
3.3. http://app.businessweek.com/UserComments/static/ratings_v2.js
4. Cookie without HttpOnly flag set
5. Cross-domain Referer leakage
Severity: | High |
Confidence: | Firm |
Host: | http://app.businessweek |
Path: | /UserComments/combo |
GET /UserComments/combo Host: app.businessweek.com Proxy-Connection: keep-alive Referer: http://www.businessweek User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 12:34:45 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Set-Cookie: JSESSIONID=77DDC444B Content-Length: 3798 benv: njbweb03 Cache-Control: s-maxage=300, max-age=300, must-revalidate Content-Type: text/html;charset=ISO <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> .reviewBlock { marg ...[SNIP]... <div id="error" style="display:none"> Error: com.businessweek.reviews ORA-06512: at "READERCOMMENTSMGR.SP ORA-06512: at line 1 </div> ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://app.businessweek |
Path: | /UserComments/combo |
GET /UserComments/combo Host: app.businessweek.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 12:39:57 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Content-Length: 3846 benv: njbweb02 Cache-Control: s-maxage=300, max-age=300, must-revalidate Content-Type: text/html;charset=ISO <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> .reviewBlock { marg ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://app.businessweek |
Path: | /UserComments/combo |
GET /UserComments/combo Host: app.businessweek.com Proxy-Connection: keep-alive Referer: http://www.businessweek User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 12:34:23 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Set-Cookie: JSESSIONID=8B869271F Content-Length: 7156 benv: njbweb03 Cache-Control: s-maxage=300, max-age=300, must-revalidate Content-Type: text/html;charset=ISO <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <input type="hidden" name="rating" id="rating" value='0' /> <script language="JavaScript" type="text/javascript" src="/UserComments/static ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://app.businessweek |
Path: | /UserComments/static |
GET /UserComments/static Host: app.businessweek.com Proxy-Connection: keep-alive Referer: http://app.businessweek User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 12:39:22 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Accept-Ranges: bytes Last-Modified: Tue, 05 Apr 2011 23:29:48 GMT Content-Length: 2117 benv: njbweb01 Cache-Control: s-maxage=300, max-age=300, must-revalidate Content-Type: text/css BODY { margin:10px !important; } .prodNav { font-weight:bold; border-top:2px solid #CCCCCC; border-bottom:2px solid #CCCCCC; margin-bottom:15px; margin-top:5px; background:#efefef; padding:3px; } .pro ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://app.businessweek |
Path: | /UserComments/static |
GET /UserComments/static Host: app.businessweek.com Proxy-Connection: keep-alive Referer: http://app.businessweek User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 12:35:33 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Accept-Ranges: bytes Last-Modified: Tue, 05 Apr 2011 23:29:48 GMT Content-Length: 521 benv: njbweb01 Cache-Control: s-maxage=300, max-age=300, must-revalidate Content-Type: text/javascript ratingImg = document.images[ ratingInput = document.getElementById( stars = new Array(); for (i = 0; i <= 10; i++) stars[i] = addImg(i); function addImg (seed) { newIm ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://app.businessweek |
Path: | /UserComments/combo |
GET /UserComments/combo Host: app.businessweek.com Proxy-Connection: keep-alive Referer: http://www.businessweek User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 12:34:23 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Set-Cookie: JSESSIONID=8B869271F Content-Length: 7156 benv: njbweb03 Cache-Control: s-maxage=300, max-age=300, must-revalidate Content-Type: text/html;charset=ISO <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://app.businessweek |
Path: | /UserComments/combo |
GET /UserComments/combo Host: app.businessweek.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 200 OK Date: Wed, 27 Apr 2011 12:39:57 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Content-Length: 3846 benv: njbweb02 Cache-Control: s-maxage=300, max-age=300, must-revalidate Content-Type: text/html;charset=ISO <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <style type="text/css"> .reviewBlock { marg ...[SNIP]... <div id="footer-inner"> <a rel="external" id="logo-bb" href="http://www <img src="http://images ...[SNIP]... <p class="company-links"> <a class="first" href="http://onlinep ...[SNIP]... </a> <a href="http://www ...[SNIP]... </a> <a class="last" href="http://onlinep ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://app.businessweek |
Path: | /UserComments/combo |
GET /UserComments/combo Host: app.businessweek.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=1.1303834675.1.1 |
HTTP/1.1 503 Service Temporarily Unavailable Date: Wed, 27 Apr 2011 18:45:14 GMT Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.31 Last-Modified: Sat, 01 May 2010 09:57:40 GMT Accept-Ranges: bytes Content-Length: 10021 benv: nybweb04 Cache-Control: s-maxage=300, max-age=300, must-revalidate Edge-Control: no-store Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http- ...[SNIP]... <a href="mailto:business_exchange ...[SNIP]... |