1. Cross-site scripting (reflected)
1.4. http://wiki.answers.com/favicon.ico [REST URL parameter 1]
1.5. http://wiki.answers.com/resources/tac.html [REST URL parameter 1]
1.6. http://wiki.answers.com/resources/tac.html [REST URL parameter 2]
2. Cleartext submission of password
3. Password field with autocomplete enabled
4. Cross-domain script include
7. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q3ccb7"><script>alert(1)< Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:38:58 GMT X-Varnish: 1013401011 Age: 0 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 80317 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... <base href="http://wiki.answers ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q/Why_are_pro_forma Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Set-Cookie: PHPSESSID=78vqi01lj6 Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:39:22 GMT X-Varnish: 1119763174 Age: 0 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 49229 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... <link rel="canonical" href="http://wiki.answers ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q/Why_are_pro_forma Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Set-Cookie: 5pce097jgmrc57a98lv6 Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:38:36 GMT X-Varnish: 1013396762 Age: 0 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 79857 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... <base href="http://wiki.answers ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /favicon.ico |
GET /favicon.ico155eb"><script>alert(1)< Host: wiki.answers.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 404 Not Found Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:37:46 GMT X-Varnish: 2077878239 Age: 0 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 42095 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... <link rel="canonical" href="http://wiki.answers ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /resources/tac.html |
GET /resources2887f"><script>alert(1)< Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://wiki.answers.com/Q Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:38:20 GMT X-Varnish: 1013393204 Age: 0 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 79141 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... <base href="http://wiki.answers ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /resources/tac.html |
GET /resources/tac.html6aece"><script>alert(1)< Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://wiki.answers.com/Q Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 404 Not Found Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:38:53 GMT X-Varnish: 1119757658 Age: 0 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 42481 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... <link rel="canonical" href="http://wiki.answers ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q/Why_are_pro_forma Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:37:29 GMT X-Varnish: 1119740398 1114574140 Age: 45405 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 79546 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... </div> <form name="registerForm" id="registerForm" action="javascript <input type=hidden name="wpCreateaccount" value="1"> ...[SNIP]... </label> <input type="password" name="wpPassword" value="" tabindex=2 id="password" /><br/> ...[SNIP]... </label> <input type="password" name="wpRetype" value="" tabindex=3 id="password2" /> </div> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q/Why_are_pro_forma Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:37:29 GMT X-Varnish: 1119740398 1114574140 Age: 45405 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 79546 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... </div> <form name="loginform" action="javascript <input type=hidden name="isBasic" value="1"> ...[SNIP]... </label> <input type="password" tabindex=2 name="wpPassword" value="" id="password" /><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q/Why_are_pro_forma Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:37:29 GMT X-Varnish: 1119740398 1114574140 Age: 45405 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 79546 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... </div> <form name="loginform" action="javascript <input type=hidden name="isBasic" value="1"> ...[SNIP]... </label> <input type="password" tabindex=2 name="wpPassword" value="" id="password" /><br/> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q/Why_are_pro_forma Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:37:29 GMT X-Varnish: 1119740398 1114574140 Age: 45405 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 79546 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... </div> <form name="registerForm" id="registerForm" action="javascript <input type=hidden name="wpCreateaccount" value="1"> ...[SNIP]... </label> <input type="password" name="wpPassword" value="" tabindex=2 id="password" /><br/> ...[SNIP]... </label> <input type="password" name="wpRetype" value="" tabindex=3 id="password2" /> </div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /Q/Why_are_pro_forma |
GET /Q/Why_are_pro_forma Host: wiki.answers.com Proxy-Connection: keep-alive Referer: http://www.answers.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Content-language: en Content-Type: text/html; charset=utf-8 Date: Fri, 11 Feb 2011 17:37:29 GMT X-Varnish: 1119740398 1114574140 Age: 45405 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 79546 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns:og="http:/ ...[SNIP]... <link rel="shortcut icon" href="/favicon.ico" /> <script src="http://en.site1 ...[SNIP]... </script> <script src="http://pagead2 </script> ...[SNIP]... </script> <script type="text/javascript" src="http://pagead2 </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | / |
TRACE / HTTP/1.0 Host: wiki.answers.com Cookie: 7ff6d991c79760f1 |
HTTP/1.1 200 OK Date: Fri, 11 Feb 2011 17:37:13 GMT Server: Apache Vary: X-Varnish,X-CLIENTIP,Host Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: wiki.answers.com Cookie: 7ff6d991c79760f1 Connection: Keep-Alive X-AnsW-rEAl-HosT: 173.193.214.243 X-CLIENTIP: 173.193.214.243 X-ORIG-URL: / X-Varnish: 1013379808 |
Severity: | Information |
Confidence: | Certain |
Host: | http://wiki.answers.com |
Path: | /favicon.ico |
GET /robots.txt HTTP/1.0 Host: wiki.answers.com |
HTTP/1.1 200 OK Server: Apache Content-Type: text/plain; charset=utf-8 Content-Length: 519 Date: Fri, 11 Feb 2011 17:37:13 GMT X-Varnish: 1013379917 962597683 Age: 290853 Via: 1.1 varnish Connection: close Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 User-Agent: * Allow: / Disallow: /Q/Special:CommunityForum Disallow: /Q/Special:SupersForum Disallow: /Q/UserDiscuss: Disallow: /Q/Special:Logs&target Disallow: /Q/Special:Search User-Ag ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://wiki.answers.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: wiki.answers.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.94 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=5pce097jgm |
HTTP/1.1 200 OK Server: Apache Last-Modified: Sun, 06 Sep 2009 09:30:51 GMT Content-Type: text/plain; charset=UTF-8 Date: Fri, 11 Feb 2011 17:37:12 GMT X-Varnish: 1119737166 1068948234 Age: 290965 Via: 1.1 varnish Connection: Keep-Alive Expires: Tue, 16 Jan 2001 00:00:00 GMT Cache-Control: private, must-revalidate, s-maxage=0, max-age=0 Vary: Accept-Encoding Content-Length: 1150 ............ .h.......(....... ..... ......................... ...[SNIP]... |