1. Cross-site scripting (reflected)
1.1. http://www.hollerclassic.com/index.htm [Referer HTTP header]
1.2. http://www.hollerclassic.com/index.htm [Referer HTTP header]
2. Cookie without HttpOnly flag set
3. Cross-domain script include
4. Content type incorrectly stated
Severity: | Low |
Confidence: | Certain |
Host: | http://www.hollerclassic |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.hollerclassic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:19:38 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d4c1830a0a00 Set-Cookie: JSESSIONID=1cb1jpmleu3fv Set-Cookie: ddcpoolid=CmsPoolP;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 54446 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms14.dealer.ddc p7072 --> <title> | New Audi, Chevrolet, Honda, Hummer, Hyundai, Mazda dealership in Winter Park, FL 32789 ...[SNIP]... tact: '', portal: '', sem: '', rlCookie: '', region: '', keyword: '', locality: 'en_US', host: '173.193.214.243', sessionReferrer: 'http://www.google.com tcdkwid: '', tcdcmpid: '', tcdadid: '', refId: '', platform: '', version: '', skin: '', templateExtra: '', type: 10, extra: 'INDEX' }; D ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.hollerclassic |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.hollerclassic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:19:37 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d4bcb70a0a00 Set-Cookie: JSESSIONID=pr05wamio9av Set-Cookie: ddcpoolid=CmsPoolP;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 54476 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms14.dealer.ddc p7072 --> <title> | New Audi, Chevrolet, Honda, Hummer, Hyundai, Mazda dealership in Winter Park, FL 32789 ...[SNIP]... <img src="http://hits.dealer ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.hollerclassic |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.hollerclassic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:19:32 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d4ab340a0a00 Set-Cookie: JSESSIONID=14ti6ep08a04b Set-Cookie: ddcpoolid=CmsPoolP;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 54316 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms14.dealer.ddc p7072 --> <title> | New Audi, Chevrolet, Honda, Hummer, Hyundai, Mazda dealership in Winter Park, FL 32789 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.hollerclassic |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.hollerclassic.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse,CookieSet Date: Sun, 17 Apr 2011 14:19:32 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: ssoid=63d4ab340a0a00 Set-Cookie: JSESSIONID=14ti6ep08a04b Set-Cookie: ddcpoolid=CmsPoolP;path=/ Expires: Thu, 01 Jan 1970 00:00:00 GMT Content-Length: 54316 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms14.dealer.ddc p7072 --> <title> | New Audi, Chevrolet, Honda, Hummer, Hyundai, Mazda dealership in Winter Park, FL 32789 ...[SNIP]... <link rel="shortcut icon" type="image/vnd.microsoft <script type="text/javascript" src="http://static.dealer ...[SNIP]... </script> <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.hollerclassic |
Path: | /smartbrowse/ajax/used |
GET /smartbrowse/ajax/used Host: www.hollerclassic.com Proxy-Connection: keep-alive Referer: http://www.hollerclassic X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/json, text/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63dda7ab0a0a00 |
HTTP/1.1 200 OK Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Vary: Accept-Encoding Date: Sun, 17 Apr 2011 14:29:48 GMT Connection: close Cache-Control: no-store Content-Length: 2177 { "SByear" : { "2011":"2011 (19)", "2010":"2010 (161)", "2009":"2009 (39)", "2008":"2008 (157)", "2007":"2007 (76)", "2006":"2006 (44)", "2005":"2005 (39)", "2004":"2004 (15)", "2003":"2003 ...[SNIP]... |