1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.newsletters |
Path: | /DRHM/servlet/Contro |
GET /DRHM/servlet/Contro Host: www.newsletters.forbes Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: ORA_WX_SESSION="10.2.2 Set-Cookie: JSESSIONID=BF38F2694 Set-Cookie: VISITOR_ID=971D4E8DF Set-Cookie: es_764.pgm="447644003a868 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 120979 Date: Tue, 03 Jan 2012 03:05:42 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc2app98 Connection: close Set-Cookie: BIGipServerp-drh-dc2pod9 <!-- REQUEST ID: TIME=1325559942764:NODE <html> <!-- BEGIN TOPHEADER --> <head> <title> Forbes Online Store - Welcome </title> ...[SNIP]... <!-- ProgramID Variable if no Session = 447644003a868--><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.newsletters |
Path: | /DRHM/servlet/Contro |
GET /DRHM/servlet/Contro Host: www.newsletters.forbes Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Moved Temporarily Location: http://www.newsletters Content-Type: text/plain Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 0 Date: Tue, 03 Jan 2012 03:05:29 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc2app96 Connection: close Set-Cookie: BIGipServerp-drh-dc2pod9 |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.newsletters |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.newsletters.forbes User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: OAX=riTaAk8CL7EACG5x; __unam=1e2567e-134a0 Content-Length: 10 |
HTTP/1.1 200 OK ETag: "37e-4b6b21a0" Content-Type: text/plain Last-Modified: Thu, 04 Feb 2010 19:36:00 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 894 Date: Wed, 07 Dec 2011 16:12:40 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc2app98 Accept-Ranges: bytes ..............h.......(.. .....tOL+. ...Q. ...[SNIP]... |