1. Cross-site scripting (reflected)
1.1. http://drh.img.digitalriver.com/DRHM/store [Action parameter]
1.2. http://drh.img.digitalriver.com/store [Action parameter]
2.3. http://drh.img.digitalriver.com/DRHM/Storefront/Site/aliphcom/cm/multimedia/s_code.js
3. Content type incorrectly stated
3.1. http://drh.img.digitalriver.com/DRHM/Storefront/Site/aliphcom/cm/images/common/EditCart.gif
3.2. http://drh.img.digitalriver.com/DRHM/Storefront/Site/aliphcom/cm/images/common/spec.gif
3.3. http://drh.img.digitalriver.com/DRHM/Storefront/Site/aliphcom/cm/images/favicona.ico
3.4. http://drh.img.digitalriver.com/DRHM/store
Severity: | High |
Confidence: | Certain |
Host: | http://drh.img.digit |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: drh.img.digitalriver.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html, */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive X-Requested-With: XMLHttpRequest Referer: http://drh.img.digit Cookie: __utma=187719549 |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Last-Modified: Tue, 17 May 2011 12:04:37 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app59 Vary: Accept-Encoding Cache-Control: max-age=86400 Expires: Wed, 18 May 2011 12:04:37 GMT Date: Tue, 17 May 2011 12:04:37 GMT Connection: close Content-Length: 42363 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <link rel="stylesheet" href="/ ...[SNIP]... ibutes: ['platform', 'miniCartImage'] } }); // Initialize the MiniCart MiniCart.init({ progressBarTop: 'DYNAMIC', errorText: 'Error:', environment: 'BASE', currentAction: 'DisplayPage98e8b';alert(1)/ nextActionParam: 'ACTION_OVERRIDE', xslUrl: '/DRHM/store?Action ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://drh.img.digit |
Path: | /store |
GET /store?Action=Displa Host: drh.img.digitalriver.com Proxy-Connection: keep-alive Referer: http://store.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html;charset=UTF-8 Last-Modified: Tue, 17 May 2011 10:58:42 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app54 Cache-Control: max-age=86400 Expires: Wed, 18 May 2011 10:58:42 GMT Date: Tue, 17 May 2011 10:58:42 GMT Connection: close Vary: Accept-Encoding Content-Length: 42404 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <link rel="stylesheet" href="/ ...[SNIP]... 'miniCartImage'] } }); // Initialize the MiniCart MiniCart.init({ progressBarTop: 'DYNAMIC', errorText: 'Error:', environment: 'BASE', currentAction: 'DisplayContentManag nextActionParam: 'ACTION_OVERRIDE', xslUrl: '/DRHM/store?Action ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://drh.img.digit |
Path: | /DRHM/Storefront/Site |
GET /DRHM/Storefront/Site Host: drh.img.digitalriver.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: s_cc=true; __utmz=187719549 |
HTTP/1.1 200 OK ETag: "15e2-4b4576f1" Content-Type: application/x-javascript Last-Modified: Thu, 07 Jan 2010 05:53:53 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app55 Cache-Control: max-age=129600 Expires: Thu, 19 May 2011 00:07:51 GMT Date: Tue, 17 May 2011 12:07:51 GMT Content-Length: 5602 Connection: close /** * DD_belatedPNG: Adds IE6 support: PNG images for CSS background-image and HTML <IMG/>. * Author: Drew Diller * Email: drew.diller@gmail.com * URL: http://www.dillerdesign * Version: 0.0.7a * Licensed under the MIT License: http://dillerdesign.com * * Example usage: * DD ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://drh.img.digit |
Path: | /DRHM/Storefront/Site |
GET /DRHM/Storefront/Site Host: drh.img.digitalriver.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: s_cc=true; __utmz=187719549 |
HTTP/1.1 200 OK ETag: "dd5-4b457709" Content-Type: application/x-javascript Last-Modified: Thu, 07 Jan 2010 05:54:17 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app52 Cache-Control: max-age=129600 Expires: Thu, 19 May 2011 00:07:51 GMT Date: Tue, 17 May 2011 12:07:51 GMT Content-Length: 3541 Connection: close /** * ------------------------- * jQuery-Plugin "pngFix" * Version: 1.2b, 09.03.2009 * by Andreas Eberhard, andreas.eberhard@gmail * http://jquery.andrea * * Copyright (c) 2007 Andreas Eberhard * Licensed under GPL (http://www.opensource * */ (function ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://drh.img.digit |
Path: | /DRHM/Storefront/Site |
GET /DRHM/Storefront/Site Host: drh.img.digitalriver.com Proxy-Connection: keep-alive Referer: http://store.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK ETag: "5003-4b8cdee8" Content-Type: application/x-javascript Last-Modified: Tue, 02 Mar 2010 09:48:24 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app55 Accept-Ranges: bytes Vary: Accept-Encoding Cache-Control: max-age=28534 Expires: Tue, 17 May 2011 18:50:43 GMT Date: Tue, 17 May 2011 10:55:09 GMT Connection: close Content-Length: 20483 /* SiteCatalyst code version: H.20.3. Copyright 1997-2009 Omniture, Inc. More info available at http://www.omniture.com */ var s_account="oneoverze var s=s_gi(s_account) /***** ...[SNIP]... =s.mr($C,(vt@tt`Zvt)`fs +"`Rm('t')`5s.p_r)s.p_r( +";s.`Q`r=n;s.t($3}`5pg){ ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://drh.img.digit |
Path: | /DRHM/Storefront/Site |
GET /DRHM/Storefront/Site Host: drh.img.digitalriver.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://store.jawbone.com Cookie: __utma=187719549 |
HTTP/1.1 200 OK ETag: "439-4b5fe590" Content-Type: image/gif Last-Modified: Wed, 27 Jan 2010 07:04:48 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 1081 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app55 Accept-Ranges: bytes Cache-Control: max-age=51750 Expires: Wed, 18 May 2011 02:28:56 GMT Date: Tue, 17 May 2011 12:06:26 GMT Connection: close .PNG . ...IHDR................(... ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://drh.img.digit |
Path: | /DRHM/Storefront/Site |
GET /DRHM/Storefront/Site Host: drh.img.digitalriver.com Proxy-Connection: keep-alive Referer: http://store.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK ETag: "d98-4b57efce" Content-Type: image/gif Last-Modified: Thu, 21 Jan 2010 06:10:22 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 3480 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app55 Accept-Ranges: bytes Cache-Control: max-age=75061 Expires: Wed, 18 May 2011 07:46:11 GMT Date: Tue, 17 May 2011 10:55:10 GMT Connection: close .PNG . ...IHDR...3......... ...... pHYs............... OiCCPPhotoshop ICC profile..x..SgTS..=...BK. ...!.........{.k........> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://drh.img.digit |
Path: | /DRHM/Storefront/Site |
GET /DRHM/Storefront/Site Host: drh.img.digitalriver.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK ETag: "57e-4d1b8428" Content-Type: text/plain Last-Modified: Wed, 29 Dec 2010 18:55:36 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 1406 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app57 Accept-Ranges: bytes Cache-Control: max-age=96612 Expires: Wed, 18 May 2011 13:48:48 GMT Date: Tue, 17 May 2011 10:58:36 GMT Connection: close ..............h.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://drh.img.digit |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: drh.img.digitalriver.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html, */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive X-Requested-With: XMLHttpRequest Referer: http://drh.img.digit Cookie: __utma=187719549 |
HTTP/1.1 200 OK Content-Type: text/css;charset=UTF-8 Last-Modified: Tue, 17 May 2011 12:04:31 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb04@dc1app57 Vary: Accept-Encoding Cache-Control: max-age=86400 Expires: Wed, 18 May 2011 12:04:32 GMT Date: Tue, 17 May 2011 12:04:32 GMT Connection: close Content-Length: 6276 <!-- REQUEST ID: TIME=1305633871934:NODE <style type="text/css"> /* popUp overlay */ .popup_window_title_bar .popu ...[SNIP]... |