1. Cross-site scripting (reflected)
1.1. https://wmp.wellington.com/wpso/OffshoreLogin.do [destination parameter]
1.2. https://wmp.wellington.com/wpso/OffshoreLogin.do [type parameter]
2. Password field with autocomplete enabled
2.1. https://wmp.wellington.com/wpso/OffshoreLogin.do
2.2. https://wmp.wellington.com/wpso/offshore/index.jsp
3.1. https://wmp.wellington.com/
3.2. https://wmp.wellington.com/chk_browser.html
3.3. https://wmp.wellington.com/wpso/OffshoreForgotLoginAndPassword.do
3.4. https://wmp.wellington.com/wpso/OffshoreLogin.do
3.5. https://wmp.wellington.com/wpso/offshore/forgot_login_password.jsp
3.6. https://wmp.wellington.com/wpso/offshore/index.jsp
4. HTML does not specify charset
4.1. https://wmp.wellington.com/
4.2. https://wmp.wellington.com/chk_browser.html
Severity: | High |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/OffshoreLogin.do |
GET /wpso/OffshoreLogin.do Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: JSESSIONID=08AE7E867 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:05:30 GMT Server: Apache Set-Cookie: JSESSIONID=688ACD40C Vary: Accept-Encoding Content-Length: 6810 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link r ...[SNIP]... <input type="hidden" name="destination" value='358ad'style='x:expression ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/OffshoreLogin.do |
GET /wpso/OffshoreLogin.do Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: JSESSIONID=08AE7E867 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:05:41 GMT Server: Apache Set-Cookie: JSESSIONID=BBFFD7239 Vary: Accept-Encoding Content-Length: 6810 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link r ...[SNIP]... <input type="hidden" name="type" value='5e7d8'style='x:expression ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/OffshoreLogin.do |
POST /wpso/OffshoreLogin.do HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: JSESSIONID=08AE7E867 Content-Type: application/x-www-form Content-Length: 88 login=werwe&password |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:52 GMT Server: Apache Set-Cookie: JSESSIONID=AFD78B227 Vary: Accept-Encoding Content-Length: 6752 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link r ...[SNIP]... <td height="405" valign="top" width="679"> <form name="ProspectLoginForm" method="POST" action="/wpso/Offsho <table width="695" border="0" cellspacing="0" cellpadding="0"> ...[SNIP]... <td width="196"> <input type="password" name="password" maxlength="20" value=""> <input type="hidden" name="destination" value=''> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/offshore/index.jsp |
GET /wpso/offshore/index.jsp HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: cookiesEnabled=yes Content-Length: 10 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:08 GMT Server: Apache Set-Cookie: JSESSIONID=3240C0FDC Vary: Accept-Encoding Content-Length: 6705 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link r ...[SNIP]... <td height="405" valign="top" width="679"> <form name="ProspectLoginForm" method="POST" action="/wpso/Offsho <table width="695" border="0" cellspacing="0" cellpadding="0"> ...[SNIP]... <td width="196"> <input type="password" name="password" maxlength="20" value=""> <input type="hidden" name="destination" value=''> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | / |
GET / HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: http://www.wellington.com Content-Length: 10 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:05 GMT Server: Apache Last-Modified: Mon, 06 Jun 2005 18:27:17 GMT ETag: "b0019-194-3f8e3da7cab40" Accept-Ranges: bytes Vary: Accept-Encoding Content-Length: 404 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Wellington Management Portfolios</title> <meta HTTP-EQUIV="Refresh" CONTENT="3; URL=js_warn.html"> <s ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /chk_browser.html |
GET /chk_browser.html HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Content-Length: 10 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:07 GMT Server: Apache Last-Modified: Fri, 29 Jul 2011 06:50:01 GMT ETag: "b0004-14eb-4a92fb0c37840 Accept-Ranges: bytes Vary: Accept-Encoding Content-Length: 5355 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Wellington Management Portfolios</title> <script language="javascript"> // var n = navigator; // string ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/OffshoreForgot |
POST /wpso/OffshoreForgot Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: JSESSIONID=0FED81A93 Content-Type: application/x-www-form Content-Length: 95 firstName=&lastName= |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:05:03 GMT Server: Apache Vary: Accept-Encoding Content-Length: 7916 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link rel="s ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/OffshoreLogin.do |
POST /wpso/OffshoreLogin.do HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: JSESSIONID=08AE7E867 Content-Type: application/x-www-form Content-Length: 88 login=werwe&password |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:52 GMT Server: Apache Set-Cookie: JSESSIONID=AFD78B227 Vary: Accept-Encoding Content-Length: 6752 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link r ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/offshore/forgot |
GET /wpso/offshore/forgot Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: JSESSIONID=0FED81A93 Content-Length: 10 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:59 GMT Server: Apache Vary: Accept-Encoding Content-Length: 7742 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link rel="s ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /wpso/offshore/index.jsp |
GET /wpso/offshore/index.jsp HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Cookie: cookiesEnabled=yes Content-Length: 10 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:08 GMT Server: Apache Set-Cookie: JSESSIONID=3240C0FDC Vary: Accept-Encoding Content-Length: 6705 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html;charset=ISO <html> <head> <BASE href='https://wmp <title>Wellington Management Portfolios</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <link r ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | / |
GET / HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: http://www.wellington.com Content-Length: 10 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:05 GMT Server: Apache Last-Modified: Mon, 06 Jun 2005 18:27:17 GMT ETag: "b0019-194-3f8e3da7cab40" Accept-Ranges: bytes Vary: Accept-Encoding Content-Length: 404 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Wellington Management Portfolios</title> <meta HTTP-EQUIV="Refresh" CONTENT="3; URL=js_warn.html"> <s ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://wmp.wellington |
Path: | /chk_browser.html |
GET /chk_browser.html HTTP/1.1 Host: wmp.wellington.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://wmp.wellington Content-Length: 10 |
HTTP/1.1 200 OK Date: Fri, 30 Dec 2011 21:04:07 GMT Server: Apache Last-Modified: Fri, 29 Jul 2011 06:50:01 GMT ETag: "b0004-14eb-4a92fb0c37840 Accept-Ranges: bytes Vary: Accept-Encoding Content-Length: 5355 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>Wellington Management Portfolios</title> <script language="javascript"> // var n = navigator; // string ...[SNIP]... |