1. Cross-site scripting (reflected)
1.1. http://www.automasterlandrover.com/smartbrowse/ajax/new.htm [REST URL parameter 1]
1.2. http://www.automasterlandrover.com/smartbrowse/ajax/new.htm [REST URL parameter 2]
1.3. http://www.automasterlandrover.com/index.htm [Referer HTTP header]
1.4. http://www.automasterlandrover.com/index.htm [Referer HTTP header]
2. Cookie without HttpOnly flag set
3. Cross-domain script include
4. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.automaste |
Path: | /smartbrowse/ajax/new.htm |
GET /smartbrowse6a13d</noscript><script Host: www.automasterlandrover Proxy-Connection: keep-alive Referer: http://www.automaste X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/json, text/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63d606fa404638 |
HTTP/1.1 404 Not Found Server: Jetty/5.1.1 (Linux/2.6.18-8.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Content-Length: 14379 Vary: Accept-Encoding Date: Sun, 17 Apr 2011 14:57:09 GMT Connection: close <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms9.pub.wc.dealer.ddc p7070 --> <title>The Automaster Land Rover | New Land Rover dealership in Shelburne, VT 05482</title ...[SNIP]... </script>c5f2daa69&20 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.automaste |
Path: | /smartbrowse/ajax/new.htm |
GET /smartbrowse/ajaxff7f2</noscript><script Host: www.automasterlandrover Proxy-Connection: keep-alive Referer: http://www.automaste X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/json, text/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63d606fa404638 |
HTTP/1.1 404 Not Found Server: Jetty/5.1.1 (Linux/2.6.18-8.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Content-Length: 14379 Vary: Accept-Encoding Date: Sun, 17 Apr 2011 14:57:09 GMT Connection: close <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms9.pub.wc.dealer.ddc p7070 --> <title>The Automaster Land Rover | New Land Rover dealership in Shelburne, VT 05482</title ...[SNIP]... </script>c5f2daa69&20 ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.automaste |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.automasterlandrover Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-8.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:21:03 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d60b7e404638 Set-Cookie: JSESSIONID=6u915eujlgvi1 Set-Cookie: ddcpoolid=CmsPoolN;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 43156 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms9.pub.wc.dealer.ddc p7070 --> <title>The Automaster Land Rover | New Land Rover dealership in Shelburne, VT 05482</title ...[SNIP]... tact: '', portal: '', sem: '', rlCookie: '', region: '', keyword: '', locality: 'en_US', host: '173.193.214.243', sessionReferrer: 'http://www.google.com tcdkwid: '', tcdcmpid: '', tcdadid: '', refId: '', platform: '', version: '', skin: '', templateExtra: '', type: 10, extra: 'INDEX' }; D ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.automaste |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.automasterlandrover Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-8.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:21:01 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d606fa404638 Set-Cookie: JSESSIONID=1o9ay8sxhs37r Set-Cookie: ddcpoolid=CmsPoolN;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 43184 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms9.pub.wc.dealer.ddc p7070 --> <title>The Automaster Land Rover | New Land Rover dealership in Shelburne, VT 05482</title ...[SNIP]... <img src="http://hits.dealer ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.automaste |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.automasterlandrover Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-8.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:20:53 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d5e768404638 Set-Cookie: JSESSIONID=52a4nq6uduepv Set-Cookie: ddcpoolid=CmsPoolN;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 43028 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms9.pub.wc.dealer.ddc p7070 --> <title>The Automaster Land Rover | New Land Rover dealership in Shelburne, VT 05482</title ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.automaste |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.automasterlandrover Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-8.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:20:53 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d5e768404638 Set-Cookie: JSESSIONID=52a4nq6uduepv Set-Cookie: ddcpoolid=CmsPoolN;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 43028 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms9.pub.wc.dealer.ddc p7070 --> <title>The Automaster Land Rover | New Land Rover dealership in Shelburne, VT 05482</title ...[SNIP]... <link rel="shortcut icon" type="image/vnd.microsoft <script type="text/javascript" src="http://static.dealer ...[SNIP]... </script> <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.automaste |
Path: | /smartbrowse/ajax/new.htm |
GET /smartbrowse/ajax/new.htm Host: www.automasterlandrover Proxy-Connection: keep-alive Referer: http://www.automaste X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/json, text/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63d606fa404638 |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-8.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Vary: Accept-Encoding Date: Sun, 17 Apr 2011 14:56:58 GMT Connection: close Cache-Control: no-store Content-Length: 563 { "SByear" : { "2011":"2011 (4)" }, "SBmake" : { "Land Rover":"Land Rover (4)" }, "SBmodel" : { "LR2":"LR2 (2)", "Range Rover Sport":"Range Rover Sport (2)" }, "SBprice" : { "36000 - 39 ...[SNIP]... |