1. Cross-site scripting (reflected)
1.1. http://mail2.creditcards.com/zimbra/ [client parameter]
1.2. http://mail2.creditcards.com/zimbra/ [client parameter]
2. Cleartext submission of password
2.1. http://mail2.creditcards.com/
2.2. http://mail2.creditcards.com/zimbra/
3.1. http://mail2.creditcards.com/zimbra/
3.2. http://mail2.creditcards.com/zimbra/css/common,login,zhtml,skin.css
3.3. http://mail2.creditcards.com/zimbra/img/logo/favicon.ico
4. Password field with autocomplete enabled
4.1. http://mail2.creditcards.com/
4.2. http://mail2.creditcards.com/zimbra/
5. Cross-domain Referer leakage
Severity: | High |
Confidence: | Certain |
Host: | http://mail2.creditcards |
Path: | /zimbra/ |
POST /zimbra/;jsessionid Host: mail2.creditcards.com Proxy-Connection: keep-alive Referer: http://mail2.creditcards Content-Length: 65 Cache-Control: max-age=0 Origin: http://mail2.creditcards User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 loginOp=login&username= |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:50 GMT Content-Type: text/html; charset=utf-8 Content-Language: en-US Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ZM_TEST=true Content-Length: 19341 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... = (it.style.display == "block" ? "none" : "block"); } function onLoad() { document.loginForm clientChange("advanceda1051";alert(1)/ } document.write("<a href='#' onclick='showWhatsThis()' id='ZLoginWhatsThisAnchor ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mail2.creditcards |
Path: | /zimbra/ |
GET /zimbra/?loginOp=login Host: mail2.creditcards.com Proxy-Connection: keep-alive Referer: http://mail2.creditcards Cache-Control: max-age=0 Origin: http://mail2.creditcards User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ZM_TEST=true; CCCID=173.193.214.243 |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:56 GMT Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=utf-8 Content-Language: en-US Set-Cookie: ZM_TEST=true Content-Length: 19275 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... y = (it.style.display == "block" ? "none" : "block"); } function onLoad() { document.loginForm clientChange("mobilea3ebc";alert(1)/ } document.write("<a href='#' onclick='showWhatsThis()' id='ZLoginWhatsThisAnchor ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mail2.creditcards |
Path: | / |
GET / HTTP/1.1 Host: mail2.creditcards.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:02 GMT Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=utf-8 Content-Language: en-US Set-Cookie: ZM_TEST=true Content-Length: 14096 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <ht ...[SNIP]... <div id="ZloginFormPanel"> <form method="post" name="loginForm" action="/zimbra/"> <input type="hidden" name="loginOp" value="login"/> ...[SNIP]... <td colspan="2" class="zLoginFieldCo <input id="password" class="zLoginField" name="password" type="password" value=""/> </td> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://mail2.creditcards |
Path: | /zimbra/ |
POST /zimbra/;jsessionid Host: mail2.creditcards.com Proxy-Connection: keep-alive Referer: http://mail2.creditcards Content-Length: 65 Cache-Control: max-age=0 Origin: http://mail2.creditcards User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 loginOp=login&username= |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:29 GMT Content-Type: text/html; charset=utf-8 Content-Language: en-US Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ZM_TEST=true Content-Length: 19321 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... <div id="ZloginFormPanel"> <form method="post" name="loginForm" action="/zimbra/"> <input type="hidden" name="loginOp" value="login"/> ...[SNIP]... <td colspan="2" class="zLoginFieldCo <input id="password" class="zLoginField" name="password" type="password" value="'"/> </td> ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://mail2.creditcards |
Path: | /zimbra/ |
POST /zimbra/;jsessionid=12m3sbtokkbl3 HTTP/1.1 Host: mail2.creditcards.com Proxy-Connection: keep-alive Referer: http://mail2.creditcards Content-Length: 65 Cache-Control: max-age=0 Origin: http://mail2.creditcards User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 loginOp=login&username= |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:29 GMT Content-Type: text/html; charset=utf-8 Content-Language: en-US Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ZM_TEST=true Content-Length: 19321 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://mail2.creditcards |
Path: | /zimbra/css/common,login |
GET /zimbra/css/common,login Host: mail2.creditcards.com Proxy-Connection: keep-alive Referer: http://mail2.creditcards User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:03 GMT Expires: Fri, 1 Jul 2011 12:55:03 GMT Cache-Control: public, max-age=604800 Vary: User-Agent Content-Type: text/css Content-Length: 39387 P,TH,TD,DIV,SELECT,INPUT HTML{width:100%;height BODY{width:100%;h ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://mail2.creditcards |
Path: | /zimbra/img/logo/favicon |
GET /zimbra/img/logo/favicon Host: mail2.creditcards.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:06 GMT Expires: Fri, 1 Jul 2011 12:55:06 GMT Cache-Control: public, max-age=604800 Content-Type: image/x-icon Last-Modified: Fri, 15 Aug 2008 17:18:06 GMT Accept-Ranges: bytes Content-Length: 894 ..............h.......(.. ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://mail2.creditcards |
Path: | / |
GET / HTTP/1.1 Host: mail2.creditcards.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:02 GMT Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Pragma: no-cache Content-Type: text/html; charset=utf-8 Content-Language: en-US Set-Cookie: ZM_TEST=true Content-Length: 14096 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <ht ...[SNIP]... <div id="ZloginFormPanel"> <form method="post" name="loginForm" action="/zimbra/"> <input type="hidden" name="loginOp" value="login"/> ...[SNIP]... <td colspan="2" class="zLoginFieldCo <input id="password" class="zLoginField" name="password" type="password" value=""/> </td> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://mail2.creditcards |
Path: | /zimbra/ |
POST /zimbra/;jsessionid Host: mail2.creditcards.com Proxy-Connection: keep-alive Referer: http://mail2.creditcards Content-Length: 65 Cache-Control: max-age=0 Origin: http://mail2.creditcards User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 loginOp=login&username= |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:29 GMT Content-Type: text/html; charset=utf-8 Content-Language: en-US Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ZM_TEST=true Content-Length: 19321 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... <div id="ZloginFormPanel"> <form method="post" name="loginForm" action="/zimbra/"> <input type="hidden" name="loginOp" value="login"/> ...[SNIP]... <td colspan="2" class="zLoginFieldCo <input id="password" class="zLoginField" name="password" type="password" value="'"/> </td> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://mail2.creditcards |
Path: | /zimbra/ |
POST /zimbra/;jsessionid Host: mail2.creditcards.com Proxy-Connection: keep-alive Referer: http://mail2.creditcards Content-Length: 65 Cache-Control: max-age=0 Origin: http://mail2.creditcards User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CCCID=173.193.214.243 loginOp=login&username= |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 12:55:29 GMT Content-Type: text/html; charset=utf-8 Content-Language: en-US Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ZM_TEST=true Content-Length: 19321 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... <td align="center" valign="middle"> <a href="http://www.zimbra ...[SNIP]... <td id="ZloginClientLeve <a target="_new" href="http://www.zimbra ...[SNIP]... |