2. Cross-domain Referer leakage
3.1. http://www.bvtservices.com/
3.2. http://www.bvtservices.com/content.php
3.3. http://www.bvtservices.com/frameset.php
3.4. http://www.bvtservices.com/navbar.php
3.5. http://www.bvtservices.com/news.php
3.6. http://www.bvtservices.com/topbar.php
4. HTML does not specify charset
4.1. http://www.bvtservices.com/
4.2. http://www.bvtservices.com/content.php
4.3. http://www.bvtservices.com/frameset.php
4.4. http://www.bvtservices.com/navbar.php
4.5. http://www.bvtservices.com/news.php
4.6. http://www.bvtservices.com/topbar.php
5. Content type incorrectly stated
5.1. http://www.bvtservices.com/css/style.txt
5.2. http://www.bvtservices.com/favicon.ico
5.3. http://www.bvtservices.com/images/scrollDown.jpg
5.4. http://www.bvtservices.com/images/scrollUp.jpg
Severity: | High |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /content.php |
GET /content.php?articleid=50' HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:39 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 3863 <html> <head> <title>ContentMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, host ...[SNIP]... </b>: 1064 (You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''50''' at line 1)<br> ...[SNIP]... |
GET /content.php?articleid=50'' HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:39 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 11458 <html> <head> <title>ContentMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, host ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /content.php |
GET /content.php?articleid=50 HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:38 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 11458 <html> <head> <title>ContentMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, host ...[SNIP]... <br> <a href="http://www ...[SNIP]... <li><a href="http://www.care2 ...[SNIP]... <li><a href="http://jerz ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.lifehack ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.stanford ...[SNIP]... <li><a href="http://www.webfoot ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://thinksi ...[SNIP]... <li><a href="http://www.pcworld ...[SNIP]... <li><a href="http://www.archives ...[SNIP]... <li> <a href="http://owl.english ...[SNIP]... <li><a href="http://securef ...[SNIP]... <p><a href="http://www.us-cert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | / |
GET / HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://burlingtonvt.net/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:24 GMT Server: Apache/2.0.46 (CentOS) Last-Modified: Wed, 30 Mar 2005 21:06:09 GMT ETag: "22804d-d8c-256df240" Accept-Ranges: bytes Content-Length: 3468 Connection: close Content-Type: text/html <html> <head> <title>BVT Services - Premiere Hosting, Information Technology Services, and Support</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burl ...[SNIP]... <meta name="publisher-email" CONTENT="info@bvtservices.com"> ...[SNIP]... <meta name="author" content="info@BVTServices.Com, http://www.BVTServices ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /content.php |
GET /content.php?articleid=4 HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:53:47 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 5767 <html> <head> <title>ContentMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, host ...[SNIP]... <meta name="publisher-email" CONTENT="info@bvtservices.com"> ...[SNIP]... <meta name="author" content="info@BVTServices.Com, http://www.BVTServices ...[SNIP]... <a href="mailto:Support@BVTServices.Com">Support@BVTServices.Com</a> ...[SNIP]... <a href="mailto:Info@BVTServices.Com">Info@BVTServices.Com</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /frameset.php |
GET /frameset.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:32 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 1579 <html> <head> <title>BVT Services - Premiere Hosting, Information Technology Services, and Support</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Bur ...[SNIP]... <meta name="publisher-email" CONTENT="info@bvtservices.com"> ...[SNIP]... <meta name="author" content="info@BVTServices.Com, http://www.BVTServices ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /navbar.php |
GET /navbar.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 9348 <html> <head> <title>MainNavMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, host ...[SNIP]... <meta name="publisher-email" CONTENT="info@bvtservices.com"> ...[SNIP]... <meta name="author" content="info@BVTServices.Com, http://www.BVTServices ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /news.php |
GET /news.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 2576 <HTML> <head> <title>NewsMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, BVTServices.Com, BVTServices,Com, BVTServices, BVT Services, BVT, hosting, ...[SNIP]... <meta name="publisher-email" CONTENT="info@bvtservices.com"> ...[SNIP]... <meta name="author" content="info@BVTServices.Com, http://www.BVTServices ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /topbar.php |
GET /topbar.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 3961 <HTML> <head> <title>TopNavMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, hosti ...[SNIP]... <meta name="publisher-email" CONTENT="info@bvtservices.com"> ...[SNIP]... <meta name="author" content="info@BVTServices.Com, http://www.BVTServices ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | / |
GET / HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://burlingtonvt.net/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:24 GMT Server: Apache/2.0.46 (CentOS) Last-Modified: Wed, 30 Mar 2005 21:06:09 GMT ETag: "22804d-d8c-256df240" Accept-Ranges: bytes Content-Length: 3468 Connection: close Content-Type: text/html <html> <head> <title>BVT Services - Premiere Hosting, Information Technology Services, and Support</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burl ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /content.php |
GET /content.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 12915 <html> <head> <title>ContentMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, host ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /frameset.php |
GET /frameset.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:32 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 1579 <html> <head> <title>BVT Services - Premiere Hosting, Information Technology Services, and Support</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Bur ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /navbar.php |
GET /navbar.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 9348 <html> <head> <title>MainNavMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, host ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /news.php |
GET /news.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 2576 <HTML> <head> <title>NewsMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, BVTServices.Com, BVTServices,Com, BVTServices, BVT Services, BVT, hosting, ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bvtservices |
Path: | /topbar.php |
GET /topbar.php HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Accept-Ranges: bytes X-Powered-By: PHP/4.3.2 Connection: close Content-Type: text/html Content-Length: 3961 <HTML> <head> <title>TopNavMod</title> <meta name="robots" content="INDEX"> <meta name="keywords" content="Vermont, Burlington, Burlingtonvt.com, BVTServices,Com, BVTServices, BVT Services, BVT, hosti ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bvtservices |
Path: | /css/style.txt |
GET /css/style.txt HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Last-Modified: Wed, 15 Jan 2003 23:13:57 GMT ETag: "4600b6-638-18397740" Accept-Ranges: bytes Content-Length: 1592 Connection: close Content-Type: text/plain <style> <!-- A { font-family: Arial, Helvetica, sans-serif; font-size: 10px; font-weight: 400; color: #000000; text-decoration: none} .copyBold { font-family: Arial, Helvetica, sans-serif; font-size ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bvtservices |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:24 GMT Server: Apache/2.0.46 (CentOS) Last-Modified: Wed, 15 Jan 2003 23:12:40 GMT ETag: "228082-37e-13a28a00" Accept-Ranges: bytes Content-Length: 894 Connection: close Content-Type: text/plain ..............h.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bvtservices |
Path: | /images/scrollDown.jpg |
GET /images/scrollDown.jpg HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Last-Modified: Wed, 15 Jan 2003 23:14:03 GMT ETag: "500060-73-189504c0" Accept-Ranges: bytes Content-Length: 115 Connection: close Content-Type: image/jpeg GIF89a.......1k................. |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bvtservices |
Path: | /images/scrollUp.jpg |
GET /images/scrollUp.jpg HTTP/1.1 Host: www.bvtservices.com Proxy-Connection: keep-alive Referer: http://www.bvtservices User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Fri, 11 Mar 2011 12:52:33 GMT Server: Apache/2.0.46 (CentOS) Last-Modified: Wed, 15 Jan 2003 23:14:03 GMT ETag: "500061-74-189504c0" Accept-Ranges: bytes Content-Length: 116 Connection: close Content-Type: image/jpeg GIF89a.......1k................. |