1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
4. Cross-domain script include
4.2. http://www.ea.com/1/product-eulas
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.ea.com |
Path: | /json/user-menu |
GET /json/user-menu?returnUrl Host: www.ea.com Proxy-Connection: keep-alive Referer: http://www.ea.com/1 X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/json, text/javascript, */*; q=0.01 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CEM-session=50ishjhd |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 13:47:02 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 727 Content-Type: text/html; charset=utf-8 {"html":"<div id=\"mod-user-menu\">\n\t ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ea.com |
Path: | /dynajs/gus.jsx |
GET /dynajs/gus.jsx HTTP/1.1 Host: www.ea.com Proxy-Connection: keep-alive Referer: http://investors.ea.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 File Not Found Date: Fri, 24 Jun 2011 13:43:43 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Set-Cookie: CEM-session=50ishjhd Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.ea.com |
Path: | /dynajs/gus.jsx |
GET /dynajs/gus.jsx HTTP/1.1 Host: www.ea.com Proxy-Connection: keep-alive Referer: http://investors.ea.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 File Not Found Date: Fri, 24 Jun 2011 13:43:43 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Set-Cookie: CEM-session=50ishjhd Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ea.com |
Path: | / |
GET / HTTP/1.1 Host: www.ea.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: __utma=103303007 |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 14:27:14 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 33296 Content-Type: text/html; charset=utf-8 <!DOCTYPE html> <html lang="en" xmlns:og="http://ogp.me <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title> ...[SNIP]... <link rel="stylesheet" type="text/css" media="screen" href="http://web-static <script type="text/javascript" src="http://use.typekit ...[SNIP]... </script> <script type="text/javascript" src="http://connect <script type="text/javascript" src="http://static.ak <script type="text/javascript" src="http://platform ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.ea.com |
Path: | /1/product-eulas |
GET /1/product-eulas HTTP/1.1 Host: www.ea.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CEM-session=50ishjhd |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 13:46:05 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 116970 Content-Type: text/html; charset=utf-8 <!DOCTYPE html> <html lang="en" xmlns:og="http://ogp.me <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title> ...[SNIP]... <link rel="stylesheet" type="text/css" media="screen" href="http://web-static <script type="text/javascript" src="http://use.typekit ...[SNIP]... </script> <script type="text/javascript" src="http://connect <script type="text/javascript" src="http://static.ak <script type="text/javascript" src="http://platform ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.ea.com |
Path: | /json/user-menu |
GET /json/user-menu?returnUrl Host: www.ea.com Proxy-Connection: keep-alive Referer: http://www.ea.com/1 X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/json, text/javascript, */*; q=0.01 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CEM-session=50ishjhd |
HTTP/1.1 200 OK Date: Fri, 24 Jun 2011 13:46:09 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.9 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 639 Content-Type: text/html; charset=utf-8 {"html":"<div id=\"mod-user-menu\">\n\t ...[SNIP]... |