1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | https://capdirect |
Path: | /affelec/soumission/VT |
GET /affelec/soumission/VT Host: capdirect.lacapitale.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=222088199 |
HTTP/1.1 200 OK Date: Fri, 17 Jun 2011 15:10:24 GMT Server: X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.9 ETag: "2ac14b2dcbec81577c0 X-Runtime: 133 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding Content-Length: 15766 Content-Type: text/html; charset=utf-8 Set-Cookie: _AffairesElectroniques Keep-Alive: timeout=5, max=100 Connection: Keep-Alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <hea ...[SNIP]... <a class="deconnect" href="/affelec/accueil ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://capdirect |
Path: | /affelec/soumission/VT |
GET /affelec/soumission/VT Host: capdirect.lacapitale.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=222088199 |
HTTP/1.1 200 OK Date: Fri, 17 Jun 2011 15:05:16 GMT Server: X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.9 ETag: "82b8ac82fae71bb5e34 X-Runtime: 127 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding Content-Length: 15764 Content-Type: text/html; charset=utf-8 Set-Cookie: _AffairesElectroniques Keep-Alive: timeout=5, max=100 Connection: Keep-Alive <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <hea ...[SNIP]... <a class="deconnect" href="/affelec/accueil ...[SNIP]... |