1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3.1. http://ondemandpreview.vportal.net/js/ajaf/20110304_135746_00000889/ajaf.js
3.2. http://ondemandpreview.vportal.net/js/global/20110304_135746_00000889/appsetup.js
3.3. http://ondemandpreview.vportal.net/js/global/20110304_135746_00000889/wddx.js
4. HTML does not specify charset
4.1. http://ondemandpreview.vportal.net/
4.2. http://ondemandpreview.vportal.net/appframe.cfm
4.3. http://ondemandpreview.vportal.net/blank.html
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://ondemandpreview |
Path: | / |
GET /?a4e26'%3balert(1)/ Host: ondemandpreview.vportal Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:45:48 GMT Server: Apache/2.2.0 (Unix) mod_ssl/2.2.0 OpenSSL/0.9.7g Set-Cookie: JSESSIONID=de30a83bc P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Connection: close Content-Type: text/html Content-Language: en-US Set-Cookie: BARRACUDA_LB_COOKIE Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="X-UA <title>OpenWorld, JavaOne ...[SNIP]... <script type="text/javascript"> APP = self.appFrame; AUX = self; direct = false; embed = false; mainURI = 'main.cfm?m=home.homepage okToLoad = true; try{ if(self.location != top.location) { // are we handling a fully resolved url but actually want to load a main frame? topPathname = top.location.pathna ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://ondemandpreview |
Path: | / |
GET / HTTP/1.1 Host: ondemandpreview.vportal Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:45:42 GMT Server: Apache/2.2.0 (Unix) mod_ssl/2.2.0 OpenSSL/0.9.7g Set-Cookie: JSESSIONID=de30d54b8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Connection: close Content-Type: text/html Content-Language: en-US Set-Cookie: BARRACUDA_LB_COOKIE Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="X-UA <title>OpenWorld, JavaOne ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ondemandpreview |
Path: | /js/ajaf/20110304_135746 |
GET /js/ajaf/20110304_135746 Host: ondemandpreview.vportal Proxy-Connection: keep-alive Referer: http://ondemandpreview Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=3e3080c0c |
HTTP/1.1 200 OK Content-Length: 188545 Content-Type: application/x-javascript Content-Location: http://ondemandpreview Last-Modified: Fri, 04 Mar 2011 21:55:08 GMT Accept-Ranges: bytes ETag: "26addbd3b6dacb1:9c6" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sun, 06 Mar 2011 14:49:26 GMT // ************************* // Version registration code. // This code produces a number of objects, which all have an identical set // of properties: // // obj.nam ...[SNIP]... at the end of the document. detectPlatform(); detectBrowser(); detectJS(); ///////////////////////// // validate.js // By: Chris Lander - chris@altuscorp.com // Copyright (c) 2002, Altus Learning Systems, Inc. // All rights reserved worldwide // // PURPOSE: // An extension to the Detection2 API. This library checks that user's computer // matches the ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ondemandpreview |
Path: | /js/global/20110304 |
GET /js/global/20110304 Host: ondemandpreview.vportal Proxy-Connection: keep-alive Referer: http://ondemandpreview Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=3e3080c0c |
HTTP/1.1 200 OK Content-Length: 17116 Content-Type: application/x-javascript Content-Location: http://ondemandpreview Last-Modified: Fri, 04 Mar 2011 21:55:08 GMT Accept-Ranges: bytes ETag: "50dde0d3b6dacb1:9c6" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sun, 06 Mar 2011 14:50:01 GMT /************************ Template Name: appsetupX.js Revision: .29 Date Modified: 6/15/2006 ************************* // js file to b ...[SNIP]... obj[i] && obj[i].indexOf( 'function' ) ){ if( typeof obj[i] == 'function' ){ copyMethod( obj, i ); str += i+' '+typeof obj[i]+'\n'; } } masterFunction( 'This is my Title', 'Sam Bennett', 'sam@altuscorp.com' ); } function getDownloadForVP( objFunc ){ // grab the data for the currently active AU, call back to supplied function var objRequest = new a_ajaxRequest( 'getDownloads', { auid: activeAU, c ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ondemandpreview |
Path: | /js/global/20110304 |
GET /js/global/20110304 Host: ondemandpreview.vportal Proxy-Connection: keep-alive Referer: http://ondemandpreview Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=3e3080c0c |
HTTP/1.1 200 OK Content-Length: 25214 Content-Type: application/x-javascript Content-Location: http://ondemandpreview Last-Modified: Fri, 04 Mar 2011 21:55:08 GMT Accept-Ranges: bytes ETag: "365cefd3b6dacb1:9c6" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sun, 06 Mar 2011 14:49:25 GMT /* * Copyright (c) 1995-2005 Macromedia, Inc. All rights reserved. */ ///////////////////////// // // Filename: wddx.js // // Authors: Simeon Simeonov (simeons@allaire.com) // Nate Weiss (nweiss@icesinc.com) // // Last Modified: February 2, 2001 // ///////////////////////// ///////////////////////// ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ondemandpreview |
Path: | / |
GET / HTTP/1.1 Host: ondemandpreview.vportal Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:45:42 GMT Server: Apache/2.2.0 (Unix) mod_ssl/2.2.0 OpenSSL/0.9.7g Set-Cookie: JSESSIONID=de30d54b8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Connection: close Content-Type: text/html Content-Language: en-US Set-Cookie: BARRACUDA_LB_COOKIE Cache-control: private <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR <html> <head> <meta http-equiv="X-UA <title>OpenWorld, JavaOne ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ondemandpreview |
Path: | /appframe.cfm |
GET /appframe.cfm HTTP/1.1 Host: ondemandpreview.vportal Proxy-Connection: keep-alive Referer: http://ondemandpreview Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=3e3080c0c |
HTTP/1.1 200 OK Connection: close Date: Sun, 06 Mar 2011 14:49:25 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Language: en-US Content-Type: text/html ...[SNIP]... </title> <meta http-equiv="Content-Type" content="text/html"/> <script type="text/javascript"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ondemandpreview |
Path: | /blank.html |
GET /blank.html HTTP/1.1 Host: ondemandpreview.vportal Proxy-Connection: keep-alive Referer: http://ondemandpreview Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=3e3080c0c |
HTTP/1.1 200 OK Content-Length: 189 Content-Type: text/html Content-Location: http://ondemandpreview Last-Modified: Fri, 04 Mar 2011 21:54:37 GMT Accept-Ranges: bytes ETag: "bc46b9c1b6dacb1:9c6" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sun, 06 Mar 2011 14:49:15 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html> <head> <title>Blank</title> </head> <body> <!-- blank page --> </body> </html> |
Severity: | Information |
Confidence: | Firm |
Host: | http://ondemandpreview |
Path: | /js/ajaf/20110304_135746 |
GET /js/ajaf/20110304_135746 Host: ondemandpreview.vportal Proxy-Connection: keep-alive Referer: http://ondemandpreview Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=3e3080c0c |
HTTP/1.1 200 OK Content-Length: 5509 Content-Type: text/plain Content-Location: http://ondemandpreview Last-Modified: Fri, 04 Mar 2011 21:55:08 GMT Accept-Ranges: bytes ETag: "e681ddd3b6dacb1:9c6" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sun, 06 Mar 2011 14:49:26 GMT 'Call Back to JS to register this VB module call registerVBModule( "vbstuff_verbose.txt", "1.0.1", "2003,3,29", "Sam Bennett" ) Function GetVersion(str) Set re = new regexp re.Pattern = " ...[SNIP]... |