1. Cross-site scripting (reflected)
2. Password field with autocomplete enabled
2.1. https://www.webimmune.net/default.asp
2.2. https://www.webimmune.net/default.asp/
3.1. https://www.webimmune.net/TempUnavailable.asp
3.2. https://www.webimmune.net/forgetpassword.asp
3.3. https://www.webimmune.net/instructions.asp
3.4. https://www.webimmune.net/preregistration.asp
3.5. https://www.webimmune.net/registration.asp
4.1. https://www.webimmune.net/TempUnavailable.asp
4.2. https://www.webimmune.net/default.asp
4.3. https://www.webimmune.net/default.asp/
4.4. https://www.webimmune.net/forgetpassword.asp
4.5. https://www.webimmune.net/instructions.asp
4.6. https://www.webimmune.net/preregistration.asp
4.7. https://www.webimmune.net/registration.asp
Severity: | High |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /PreRegistration.asp |
GET /PreRegistration.asp Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:13:35 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 9775 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... ) { document.location = "./registration.asp"; } function LeaveMe() { document.location = "./default.asp"; } alert('You must register before you can request your password.219be'-alert(1)- </SCRIPT> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /default.asp |
GET /default.asp HTTP/1.1 Host: www.webimmune.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Aug 2011 17:08:17 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 11314 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... <td> <form action="./validateLogin <TABLE ID="Table2"> ...[SNIP]... <TD> <input type="password" size="20" name="password" CLASS="forminput1" ID="Password1"> </TD> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /default.asp/ |
GET /default.asp/ HTTP/1.1 Host: www.webimmune.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Aug 2011 17:08:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 11314 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... <td> <form action="./validateLogin <TABLE ID="Table2"> ...[SNIP]... <TD> <input type="password" size="20" name="password" CLASS="forminput1" ID="Password1"> </TD> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /TempUnavailable.asp |
GET /TempUnavailable.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:13:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 8560 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... <a href="mailto:virus_research@avertlabs ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /forgetpassword.asp |
GET /forgetpassword.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:12:38 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 10550 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... value.indexOf (' ') != -1) || (TheForm.Email_Address ErrorMsg += "- Email Address\n For example: yourname@domain.com\n" } if ( ErrorMsg.length > ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /instructions.asp |
GET /instructions.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:13:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 4821 Content-Type: text/html Cache-control: private <html> <head> <title>Instructions< <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> </head> <link rel="stylesheet" type="text/css" href="css/main_global.css ...[SNIP]... <a href="mailto: Virus_Research@avertlabs Virus_Research@avertlabs ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /preregistration.asp |
GET /preregistration.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:12:13 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 9682 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... <A href="mailto:Virus_Research@avertlabs </A> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /registration.asp |
GET /registration.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:12:29 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 39518 Content-Type: text/html Expires: Wed, 24 Aug 2011 17:12:29 GMT Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... TheForm.Email_Address TheForm.Email_Address ErrorMsg += "- Email Address\n For example: yourname@domain.com\n" if (TheForm.Email_Address ErrorMsg += "- Confirm Address\n Does not match the Email Address\n" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /TempUnavailable.asp |
GET /TempUnavailable.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:13:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 8560 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /default.asp |
GET /default.asp HTTP/1.1 Host: www.webimmune.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Aug 2011 17:08:17 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 11314 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /default.asp/ |
GET /default.asp/ HTTP/1.1 Host: www.webimmune.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Wed, 24 Aug 2011 17:08:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 11314 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /forgetpassword.asp |
GET /forgetpassword.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:12:38 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 10550 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /instructions.asp |
GET /instructions.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:13:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 4821 Content-Type: text/html Cache-control: private <html> <head> <title>Instructions< <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> </head> <link rel="stylesheet" type="text/css" href="css/main_global.css ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /preregistration.asp |
GET /preregistration.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:12:13 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 9682 Content-Type: text/html Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://www.webimmune.net |
Path: | /registration.asp |
GET /registration.asp HTTP/1.1 Host: www.webimmune.net Connection: keep-alive Referer: https://www.webimmune.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDQSAAATBS |
HTTP/1.1 200 OK Date: Wed, 24 Aug 2011 17:12:29 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 39518 Content-Type: text/html Expires: Wed, 24 Aug 2011 17:12:29 GMT Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>McAfee Avert ...[SNIP]... |