1. Cross-site scripting (reflected)
2. Cross-domain Referer leakage
Severity: | High |
Confidence: | Certain |
Host: | http://www.templatehelp |
Path: | /pr_interface.php |
GET /pr_interface.php?cols=4 Host: www.templatehelp.com Proxy-Connection: keep-alive Referer: http://www.webmaster User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=239nok7hbd |
HTTP/1.1 200 OK Server: nginx/0.8.54 Date: Sat, 04 Jun 2011 12:08:29 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 10786 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" > <title>Templates Search Results</title> <script type= ...[SNIP]... <body onload="remove_loading(); ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.templatehelp |
Path: | /pr_interface.php |
GET /pr_interface.php?cols=4 Host: www.templatehelp.com Proxy-Connection: keep-alive Referer: http://www.webmaster User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=239nok7hbd |
HTTP/1.1 200 OK Server: nginx/0.8.54 Date: Sat, 04 Jun 2011 12:08:13 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 10194 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" > <title>Templates Search Results</title> <script type= ...[SNIP]... <td> <img class="template onclick="javascript </td> ...[SNIP]... <td> <img class="template onclick="javascript </td> ...[SNIP]... <td> <img class="template onclick="javascript </td> ...[SNIP]... <td> <img class="template onclick="javascript </td> ...[SNIP]... |