1. Cross-site scripting (reflected)
1.1. https://ssl.manitu.de/cgi/webhosting/orderassistant/orderassistant.cgi [domain_0 parameter]
Severity: | High |
Confidence: | Certain |
Host: | https://ssl.manitu.de |
Path: | /cgi/webhosting |
GET /cgi/webhosting Host: ssl.manitu.de Connection: keep-alive Referer: https://ssl.manitu.de/cgi Cache-Control: max-age=0 Origin: https://ssl.manitu.de User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.134 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 17 Mar 2011 15:45:58 GMT Server: Apache/1.3.41 manitu (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8j PHP/5.2.17 mod_auth_pam_external/0.1 FrontPage/4.0.4.3 mod_perl/1.29 Keep-Alive: timeout=15 Connection: Keep-Alive Content-Type: text/html Content-Length: 5859 <HTML> <HEAD> <TITLE>Online-Bestel <META HTTP-EQUIV="content-type" CONTENT="text/html; charset=ISO-8859-1"> </HEAD> <LINK REL="stylesheet" TYPE="text/css" HREF="https://ssl.ma ...[SNIP]... <INPUT NAME="domain_0" TYPE="text" VALUE="erhg erhgersg1db1a"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ssl.manitu.de |
Path: | /cgi/webhosting |
GET /cgi/webhosting Host: ssl.manitu.de Connection: keep-alive Referer: https://ssl.manitu.de/cgi Cache-Control: max-age=0 Origin: https://ssl.manitu.de User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.134 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 17 Mar 2011 15:46:07 GMT Server: Apache/1.3.41 manitu (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8j PHP/5.2.17 mod_auth_pam_external/0.1 FrontPage/4.0.4.3 mod_perl/1.29 Keep-Alive: timeout=15 Connection: Keep-Alive Content-Type: text/html Content-Length: 5859 <HTML> <HEAD> <TITLE>Online-Bestel <META HTTP-EQUIV="content-type" CONTENT="text/html; charset=ISO-8859-1"> </HEAD> <LINK REL="stylesheet" TYPE="text/css" HREF="https://ssl.ma ...[SNIP]... <input type="text" name="kkauthinfocode_0" value="aws fafe79bf"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ssl.manitu.de |
Path: | / |
TRACE / HTTP/1.0 Host: ssl.manitu.de Cookie: db732173f1778647 |
HTTP/1.1 200 OK Date: Thu, 17 Mar 2011 15:44:54 GMT Server: Apache/1.3.41 manitu (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8j PHP/5.2.17 mod_auth_pam_external/0.1 FrontPage/4.0.4.3 mod_perl/1.29 Connection: close Content-Type: message/http TRACE / HTTP/1.0 Cookie: db732173f1778647 Host: ssl.manitu.de |
Severity: | Information |
Confidence: | Certain |
Host: | https://ssl.manitu.de |
Path: | /cgi/webhosting |
GET /cgi/webhosting Host: ssl.manitu.de Connection: keep-alive Referer: http://www.manitu.de User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.134 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 17 Mar 2011 15:44:53 GMT Server: Apache/1.3.41 manitu (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8j PHP/5.2.17 mod_auth_pam_external/0.1 FrontPage/4.0.4.3 mod_perl/1.29 Keep-Alive: timeout=15 Connection: Keep-Alive Content-Type: text/html Content-Length: 2180 <HTML> <HEAD> <TITLE>Online-Bestel <META HTTP-EQUIV="content-type" CONTENT="text/html; charset=ISO-8859-1"> </HEAD> <LINK REL="stylesheet" TYPE="text/css" HREF="https://ssl.ma ...[SNIP]... <A HREF="mailto:info@manitu.de">info@manitu.de</A> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ssl.manitu.de |
Path: | /cgi/webhosting |
GET /robots.txt HTTP/1.0 Host: ssl.manitu.de |
HTTP/1.1 200 OK Date: Thu, 17 Mar 2011 15:44:55 GMT Server: Apache/1.3.41 manitu (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8j PHP/5.2.17 mod_auth_pam_external/0.1 FrontPage/4.0.4.3 mod_perl/1.29 Last-Modified: Mon, 12 Apr 2010 07:16:51 GMT ETag: "85018a-19-4bc2c8e3" Accept-Ranges: bytes Content-Length: 25 Connection: close Content-Type: text/plain User-agent: * Allow: / |
Severity: | Information |
Confidence: | Certain |
Host: | https://ssl.manitu.de |
Path: | /cgi/webhosting |
GET /cgi/webhosting Host: ssl.manitu.de Connection: keep-alive Referer: http://www.manitu.de User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.134 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Thu, 17 Mar 2011 15:44:53 GMT Server: Apache/1.3.41 manitu (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8j PHP/5.2.17 mod_auth_pam_external/0.1 FrontPage/4.0.4.3 mod_perl/1.29 Keep-Alive: timeout=15 Connection: Keep-Alive Content-Type: text/html Content-Length: 2180 <HTML> <HEAD> <TITLE>Online-Bestel <META HTTP-EQUIV="content-type" CONTENT="text/html; charset=ISO-8859-1"> </HEAD> <LINK REL="stylesheet" TYPE="text/css" HREF="https://ssl.ma ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ssl.manitu.de |
Path: | / |
Issued to: | ssl.manitu.de |
Issued by: | Thawte Server CA |
Valid from: | Wed Jun 23 19:00:00 CDT 2010 |
Valid to: | Wed Aug 22 18:59:59 CDT 2012 |
Issued to: | Thawte Server CA |
Issued by: | Thawte Server CA |
Valid from: | Wed Jul 31 19:00:00 CDT 1996 |
Valid to: | Fri Jan 01 17:59:59 CST 2021 |