1. Cross-site scripting (reflected)
1.4. https://www.reliant.com/en_US/Page/Shop/Public/bus_shop_landing_page.jsp [language_code cookie]
Severity: | High |
Confidence: | Certain |
Host: | https://www.reliant.com |
Path: | /en_US/Page/Shop/Public |
GET /en_US/Page/Shop/Public Host: www.reliant.com Connection: keep-alive Referer: https://www.reliant.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: i_chronicle_id=09017 |
HTTP/1.1 200 OK Server: Oracle-iPlanet-Web-Server Date: Thu, 18 Aug 2011 22:14:08 GMT Cache-control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache Set-cookie: language_code=en_US; Domain=.reliant.com; Path=/ Set-cookie: i_chronicle_id=09017 Set-cookie: site_location=Shop; Domain=.reliant.com; Path=/ Set-cookie: CurrentAccountSegment Content-type: text/html;charset=utf-8 Via: 1.1 https-www.reliant.com Proxy-agent: Oracle-iPlanet-Web-Server Content-Length: 64023 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... // Get key navigation values var SUB_NAV_ROOT_ID = ''; var SUB_NAV_ROOT_NAME = ''; var SUB_NAV_ID = ''; var LANGUAGE_CODE = COOKIE_SET['language_code var MSG_CODE='|browser --> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.reliant.com |
Path: | /en_US/Page/Shop/Public |
GET /en_US/Page/Shop/Public Host: www.reliant.com Connection: keep-alive Referer: http://www.nydailynews User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Oracle-iPlanet-Web-Server Date: Thu, 18 Aug 2011 22:13:33 GMT Cache-control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-cookie: JSESSIONID=347A33EAC Set-cookie: language_code=en_US; Domain=.reliant.com; Path=/ Set-cookie: i_chronicle_id=09017 Set-cookie: site_location=Shop; Domain=.reliant.com; Path=/ Set-cookie: CurrentAccountSegment Pragma: no-cache Content-type: text/html;charset=utf-8 Via: 1.1 https-www.reliant.com Proxy-agent: Oracle-iPlanet-Web-Server Content-Length: 63954 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... ms[0] var protocol = "http" if (protocol == "http" || protocol == "HTTP") { aForm.action = 'http:///en_US/Page/Shop aForm.submit(); } } function addleadingZero(str) { var numbr =""; if (str.length < 2 ) { numbr = "0" + str } else { numbr = str; } ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.reliant.com |
Path: | /en_US/Page/Shop/Public |
GET /en_US/Page/Shop/Public Host: www.reliant.com Connection: keep-alive Referer: http://www.nydailynews User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Server: Oracle-iPlanet-Web-Server Date: Thu, 18 Aug 2011 22:13:20 GMT Cache-control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache Set-cookie: language_code=en_US; Domain=.reliant.com; Path=/ Set-cookie: i_chronicle_id=09017 Set-cookie: site_location=Shop; Domain=.reliant.com; Path=/ Set-cookie: CurrentAccountSegment Content-type: text/html;charset=utf-8 Via: 1.1 https-www.reliant.com Proxy-agent: Oracle-iPlanet-Web-Server Content-Length: 63951 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... rms[0] var protocol = "http" if (protocol == "http" || protocol == "HTTP") { aForm.action = 'http:///en_US/Page/Shop aForm.submit(); } } function addleadingZero(str) { var numbr =""; if (str.length < 2 ) { numbr = "0" + str } else { numbr = str; } ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.reliant.com |
Path: | /en_US/Page/Shop/Public |
GET /en_US/Page/Shop/Public Host: www.reliant.com Connection: keep-alive Referer: https://www.reliant.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: i_chronicle_id=09017 |
HTTP/1.1 200 OK Server: Oracle-iPlanet-Web-Server Date: Thu, 18 Aug 2011 22:15:15 GMT Cache-control: no-cache Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache Set-cookie: language_code=en_US; Domain=.reliant.com; Path=/ Set-cookie: i_chronicle_id=09017 Set-cookie: site_location=Shop; Domain=.reliant.com; Path=/ Set-cookie: CurrentAccountSegment Content-type: text/html;charset=utf-8 Via: 1.1 https-www.reliant.com Proxy-agent: Oracle-iPlanet-Web-Server Content-Length: 27012 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... .PASSWORD.value != "") { mykey = aForm.PASSWORD.value; } aForm.target.value = ("https://www.reliant.com aForm.action = "https://www.reliant.com //Comment and uncomment incase of site maintenance //aForm.action = "https://www.reliant.com ...[SNIP]... |