2. Cross-site scripting (reflected)
2.1. http://gw.vtrenz.net/ [mode parameter]
2.2. http://gw.vtrenz.net/ [mode parameter]
2.3. http://gw.vtrenz.net/ [mode parameter]
2.4. http://gw.vtrenz.net/ [name of an arbitrarily supplied request parameter]
2.5. http://gw.vtrenz.net/ [name of an arbitrarily supplied request parameter]
2.6. http://gw.vtrenz.net/ [name of an arbitrarily supplied request parameter]
2.7. http://gw.vtrenz.net/ [q14 parameter]
2.8. http://gw.vtrenz.net/ [q14 parameter]
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Tentative |
Host: | http://gw.vtrenz.net |
Path: | / |
GET /?KTFSQAXD2J HTTP/1.1 Host: gw.vtrenz.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=983040619 |
HTTP/1.1 500 Server Error Connection: close Date: Tue, 08 Mar 2011 02:57:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=37851635;expires=Thu Set-Cookie: CFTOKEN=ea786198298cad6 Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Conten ...[SNIP]... |
GET /?KTFSQAXD2J HTTP/1.1 Host: gw.vtrenz.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=983040619 |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 02:57:35 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=37851651;expires=Thu Set-Cookie: CFTOKEN=16015cdbed277e9c Expires: Tue, 08 Mar 2011 02:57:35 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter for Recruiters: How To, Help and Hype</title> <meta name="description" content="" /> <meta name="keywords" content="Bullhorn Twitter" /> <meta ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | / |
POST /?method=cSurveyWebs Host: gw.vtrenz.net Proxy-Connection: keep-alive Referer: http://gw.vtrenz.net/ Cache-Control: max-age=0 Origin: http://gw.vtrenz.net Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=983040619 Content-Length: 224 formRelocateURL= ...[SNIP]... |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 03:02:30 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Expires: Tue, 08 Mar 2011 03:02:30 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter Sign up Form</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/h ...[SNIP]... <a href="http://gw.vtrenz ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | / |
POST /?method=cSurveyWebs Host: gw.vtrenz.net Proxy-Connection: keep-alive Referer: http://gw.vtrenz.net/ Cache-Control: max-age=0 Origin: http://gw.vtrenz.net Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=983040619 Content-Length: 224 formRelocateURL= ...[SNIP]... |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 03:02:57 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Expires: Tue, 08 Mar 2011 03:02:57 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter Sign up Form</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/h ...[SNIP]... <a href="http://gw.vtrenz ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | / |
GET /?method=cSurveyWebs Host: gw.vtrenz.net Proxy-Connection: keep-alive Referer: http://gw.vtrenz.net/ Cache-Control: max-age=0 Origin: http://gw.vtrenz.net Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=983040619 |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 03:06:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Expires: Tue, 08 Mar 2011 03:06:16 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter Sign up Form</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/h ...[SNIP]... <a href="http://gw.vtrenz ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | / |
GET /?GTJ25UFT6K&85df9</script><script Host: gw.vtrenz.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 02:40:21 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=37849852;expires=Thu Set-Cookie: CFTOKEN=2332d0e648bdb92b Set-Cookie: JSESSIONID=9830e6829 Set-Cookie: CFID=37849853;expires=Thu Set-Cookie: CFTOKEN=def3335b2f66aa06 Expires: Tue, 08 Mar 2011 02:40:21 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter Sign up Form</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/ht ...[SNIP]... <script type="text/javascript" language="javascript"> VTRENZ = {}; VTRENZ.gwParams = {}; VTRENZ.gwParams["85df9</script><script </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | / |
GET /?S2J9YX6ANY&%0019322</script><script Host: gw.vtrenz.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=983040619 |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 02:52:51 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Expires: Tue, 08 Mar 2011 02:52:51 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>LPHSE2011Trends PR Social Media</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" conte ...[SNIP]... <script type="text/javascript" language="javascript"> VTRENZ = {}; VTRENZ.gwParams = {}; VTRENZ.gwParams[".19322</script><script </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | / |
GET /?KTFSQAXD2J&6a9be</script><script Host: gw.vtrenz.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=983040619 |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 02:58:48 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Expires: Tue, 08 Mar 2011 02:58:48 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter for Recruiters: How To, Help and Hype</title> <meta name="description" content="" /> <meta name="keywords" content="Bullhorn Twitter" /> <meta ...[SNIP]... <script type="text/javascript" language="javascript"> VTRENZ = {}; VTRENZ.gwParams = {}; VTRENZ.gwParams["6a9be</script><script </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | / |
POST /?method=cSurveyWebs Host: gw.vtrenz.net Proxy-Connection: keep-alive Referer: http://gw.vtrenz.net/ Cache-Control: max-age=0 Origin: http://gw.vtrenz.net Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=983040619 Content-Length: 224 formRelocateURL= |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 03:11:38 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Expires: Tue, 08 Mar 2011 03:11:38 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter Sign up Form</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/h ...[SNIP]... <iframe src="http://www.bullhorn ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://gw.vtrenz.net |
Path: | / |
POST /?method=cSurveyWebs Host: gw.vtrenz.net Proxy-Connection: keep-alive Referer: http://gw.vtrenz.net/ Cache-Control: max-age=0 Origin: http://gw.vtrenz.net Content-Type: application/x-www-form Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=983040619 Content-Length: 224 formRelocateURL= |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 03:15:37 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Expires: Tue, 08 Mar 2011 03:15:37 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter Sign up Form</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/h ...[SNIP]... <iframe src="http://www.bullhorn ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://gw.vtrenz.net |
Path: | / |
GET /?GTJ25UFT6K HTTP/1.1 Host: gw.vtrenz.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Connection: close Date: Tue, 08 Mar 2011 02:39:59 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=37849794;expires=Thu Set-Cookie: CFTOKEN=968c073b8df5619f Set-Cookie: JSESSIONID=98309ef87 Set-Cookie: CFID=37849795;expires=Thu Set-Cookie: CFTOKEN=22bb2e18bfd08917 Expires: Tue, 08 Mar 2011 02:39:59 GMT Content-Type: text/html; charset=UTF-8 <html> <head> <title>Twitter Sign up Form</title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/ht ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://gw.vtrenz.net |
Path: | /scripts/validator |
GET /scripts/validator Host: gw.vtrenz.net Proxy-Connection: keep-alive Referer: http://gw.vtrenz.net/ Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=983040619 |
HTTP/1.1 200 OK Content-Length: 23292 Content-Type: application/x-javascript Content-Location: http://gw.vtrenz.net Last-Modified: Fri, 29 Jan 2010 23:00:43 GMT Accept-Ranges: bytes ETag: "281ab4e236a1ca1:474" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Tue, 08 Mar 2011 02:39:59 GMT /*======================= * Form Validator v2.0 * Copyright (c)2004 - 2006 Vtrenz, Inc. * * Date: 08/13/2004 * Written By: JD Hendrickson & Rob Johnson * * Last Updated: ...[SNIP]... ; } } //======================= /************************ Object: Field Author: Rob Johnson Email: rjohnson@vtrenz.com Created: Aug. 12, 2004 Brief Desc: The Field object represents a field in an html form. The Field object can be used to define a field's data type, format, and requirements. **** ...[SNIP]... |