1. Cross-site scripting (reflected)
2. SSL cookie without secure flag set
3. Cookie without HttpOnly flag set
4. Password field with autocomplete enabled
4.1. https://www.huntsmanservice.com/portal/page/portal/EBUSINESS_GENERAL_PGR/LOGIN_PORTAL_PG
4.2. https://www.huntsmanservice.com/portal/page/portal/EBUSINESS_GENERAL_PGR/LOGIN_PORTAL_PG
Severity: | High |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | /portal/page/portal |
GET /portal/page/portal Host: www.huntsmanservice.com Connection: keep-alive Referer: https://www.huntsman User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ORA_WX_SESSION= |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: max-age=0 Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Date: Tue, 17 May 2011 13:51:33 GMT Content-Location: /servlet/page/EBUSINESS Content-Length: 57407 <HTML dir=LTR> <HEAD> <TITLE>HuntsmanService Login Page</TITLE> <style type="text/css"> .GroupHeaderLinkid1s ...[SNIP]... <FORM ACTION="https://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | /portal/pls/portal/PORTAL |
GET /portal/pls/portal71bf5<img%20src%3da Host: www.huntsmanservice.com Connection: keep-alive Referer: https://www.huntsman User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ORA_WX_SESSION= |
HTTP/1.1 404 Not Found Cache-Control: private Content-Type: text/html; charset=ISO-8859-1 Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Content-Length: 299 Date: Tue, 17 May 2011 13:53:32 GMT Content-Location: /servlet/RepositoryS <HTML><HEAD><TITLE>404 Not Found</TITLE></HEAD><BODY ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | /portal/pls/portal71bf5 |
GET /portal/pls/portal71bf5 Host: www.huntsmanservice.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.huntsman |
HTTP/1.1 404 Not Found Cache-Control: private Content-Type: text/html; charset=ISO-8859-1 Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Content-Length: 369 Date: Tue, 17 May 2011 14:13:51 GMT Content-Location: /servlet/RepositoryS <HTML><HEAD><TITLE>404 Not Found</TITLE></HEAD><BODY ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://www.huntsman |
Path: | / |
GET / HTTP/1.1 Host: www.huntsmanservice.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Moved Temporarily Location: /portal/pls/portal/portal Cache-Control: max-age=0 Content-Type: text/plain Set-Cookie: ORA_WX_SESSION= Set-Cookie: portal=9.0.3+en-us+us Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Content-Length: 0 Date: Tue, 17 May 2011 13:50:41 GMT Content-Location: /servlet/RepositoryS |
Severity: | Low |
Confidence: | Firm |
Host: | https://www.huntsman |
Path: | / |
GET / HTTP/1.1 Host: www.huntsmanservice.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Moved Temporarily Location: /portal/pls/portal/portal Cache-Control: max-age=0 Content-Type: text/plain Set-Cookie: ORA_WX_SESSION= Set-Cookie: portal=9.0.3+en-us+us Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Content-Length: 0 Date: Tue, 17 May 2011 13:50:41 GMT Content-Location: /servlet/RepositoryS |
Severity: | Low |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | /portal/page/portal |
GET /portal/page/portal Host: www.huntsmanservice.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ORA_WX_SESSION= |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: max-age=0 Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Date: Tue, 17 May 2011 13:50:47 GMT Content-Location: /servlet/page/EBUSINESS Content-Length: 59387 <HTML dir=LTR> <HEAD> <TITLE>HuntsmanService Login Page</TITLE> <style type="text/css"> .GroupHeaderLinkid1s ...[SNIP]... <div class="WrapperA"> <FORM ACTION="https://www <INPUT TYPE="hidden" NAME="p_action" VALUE="CANCEL"> ...[SNIP]... <TD><INPUT TYPE="password" NAME="p_pwd" class="feedbacksmall" onKeyPress="return submitenter(this,event)"></TD> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | /portal/page/portal |
GET /portal/page/portal Host: www.huntsmanservice.com Connection: keep-alive Referer: https://www.huntsman User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ORA_WX_SESSION= |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: max-age=0 Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Date: Tue, 17 May 2011 13:51:06 GMT Content-Location: /servlet/page/EBUSINESS Content-Length: 58558 <HTML dir=LTR> <HEAD> <TITLE>HuntsmanService Login Page</TITLE> <style type="text/css"> .GroupHeaderLinkid1s ...[SNIP]... <div class="WrapperA"> <FORM ACTION="https://www <INPUT TYPE="hidden" NAME="p_action" VALUE="CANCEL"> ...[SNIP]... <TD><INPUT TYPE="password" NAME="p_pwd" class="feedbacksmall" onKeyPress="return submitenter(this,event)"></TD> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | / |
TRACE / HTTP/1.0 Host: www.huntsmanservice.com Cookie: bf21ac58d669c494 |
HTTP/1.1 200 OK Content-Type: message/http Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Content-Length: 101 Date: Tue, 17 May 2011 13:50:47 GMT TRACE / HTTP/1.1 Connection: Keep-Alive Cookie: bf21ac58d669c494 Host: www.huntsmanservice.com |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | /portal/page/portal |
GET /portal/page/portal Host: www.huntsmanservice.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ORA_WX_SESSION= |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: max-age=0 Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Date: Tue, 17 May 2011 13:50:47 GMT Content-Location: /servlet/page/EBUSINESS Content-Length: 59387 <HTML dir=LTR> <HEAD> <TITLE>HuntsmanService Login Page</TITLE> <style type="text/css"> .GroupHeaderLinkid1s ...[SNIP]... <A HREF="mailto:huntsman_service@huntsman ...[SNIP]... <br>Contact your customer service representative or send an email to huntsman_service@huntsman ...[SNIP]... <A HREF="mailto:huntsman_service@huntsman ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | /portal/page/portal |
GET /portal/page/portal Host: www.huntsmanservice.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ORA_WX_SESSION= |
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Cache-Control: max-age=0 Connection: Keep-Alive Keep-Alive: timeout=5, max=999 Server: Oracle-Application-Server Date: Tue, 17 May 2011 13:50:47 GMT Content-Location: /servlet/page/EBUSINESS Content-Length: 59387 <HTML dir=LTR> <HEAD> <TITLE>HuntsmanService Login Page</TITLE> <style type="text/css"> .GroupHeaderLinkid1s ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.huntsman |
Path: | / |
Issued to: | www.huntsmanservice.com |
Issued by: | VeriSign Class 3 International Server CA - G3 |
Valid from: | Sun Oct 24 19:00:00 CDT 2010 |
Valid to: | Tue Oct 25 18:59:59 CDT 2011 |
Issued to: | VeriSign Class 3 International Server CA - G3 |
Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Valid from: | Sun Feb 07 18:00:00 CST 2010 |
Valid to: | Fri Feb 07 17:59:59 CST 2020 |
Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Issued by: | Class 3 Public Primary Certification Authority |
Valid from: | Tue Nov 07 18:00:00 CST 2006 |
Valid to: | Sun Nov 07 17:59:59 CST 2021 |
Issued to: | Class 3 Public Primary Certification Authority |
Issued by: | Class 3 Public Primary Certification Authority |
Valid from: | Sun Jan 28 18:00:00 CST 1996 |
Valid to: | Wed Aug 02 18:59:59 CDT 2028 |