1. Cross-site scripting (reflected)
1.1. http://www.gillmanauto.com/smartbrowse/ajax/used.htm [REST URL parameter 1]
1.2. http://www.gillmanauto.com/smartbrowse/ajax/used.htm [REST URL parameter 2]
1.3. http://www.gillmanauto.com/index.htm [Referer HTTP header]
1.4. http://www.gillmanauto.com/index.htm [Referer HTTP header]
2. Cookie without HttpOnly flag set
2.1. http://www.gillmanauto.com/index.htm
2.2. http://www.gillmanauto.com/apps/video/player/ddcVideoPlayer_np.swf
2.3. http://www.gillmanauto.com/shows/slideshows/01d4bb5f0a0a008901604a9e791b529a.xml
2.4. http://www.gillmanauto.com/sites/g/gillmanauto/images/v8-siteheader-default.swf
2.5. http://www.gillmanauto.com/v8/templates/139/images/red_white/facebook-icon.gif
2.6. http://www.gillmanauto.com/v8/widgets/generic/image/semantic-slideshow.swf
3. Cross-domain script include
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /smartbrowse/ajax/used |
GET /smartbrowse3025a</noscript><script Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/json, text/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 404 Not Found Date: Sun, 17 Apr 2011 14:42:43 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.7.1.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Content-Length: 13660 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms26.dealer.ddc p7070 --> <title>Gillman Acura, Honda, Nissan, Mitsubishi, Chevrolet, Subaru, Chrysler, Jeep, Dodge, GMC, ...[SNIP]... </script>1fec5e9f872& ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /smartbrowse/ajax/used |
GET /smartbrowse/ajaxaaedb</noscript><script Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/json, text/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 404 Not Found Date: Sun, 17 Apr 2011 14:42:44 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.7.1.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Content-Length: 13660 <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms26.dealer.ddc p7070 --> <title>Gillman Acura, Honda, Nissan, Mitsubishi, Chevrolet, Subaru, Chrysler, Jeep, Dodge, GMC, ...[SNIP]... </script>1fec5e9f872& ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.gillmanauto.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:17:57 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 Connection: close P3P: "https://secure4.dealer Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ssoid=63d339870a0a00 Content-Type: text/html;charset=iso Set-Cookie: JSESSIONID=1qt0ejmih4m4o Set-Cookie: lbpoolmember=3607170570 X-DDC-Arch-Trace: ,HttpResponse,CookieSet Set-Cookie: ddcpoolid=CmsPoolA;path=/ <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms21.dealer.ddc p7070 --> <title>Gillman Acura, Honda, Nissan, Mitsubishi, Chevrolet, Subaru, Chrysler, Jeep, Dodge, GMC, ...[SNIP]... <img src="http://hits.dealer ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.gillmanauto.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:18:13 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.7.1.el5 i386 java/1.5.0_16 Connection: close P3P: "https://secure4.dealer Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ssoid=63d376310a0a00 Content-Type: text/html;charset=iso Set-Cookie: JSESSIONID=491h82iwsa0mj Set-Cookie: lbpoolmember=1728122378 X-DDC-Arch-Trace: ,HttpResponse,CookieSet Set-Cookie: ddcpoolid=CmsPoolA;path=/ <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms26.dealer.ddc p7070 --> <title>Gillman Acura, Honda, Nissan, Mitsubishi, Chevrolet, Subaru, Chrysler, Jeep, Dodge, GMC, ...[SNIP]... tact: '', portal: '', sem: '', rlCookie: '', region: '', keyword: '', locality: 'en_US', host: '173.193.214.243', sessionReferrer: 'http://www.google.com tcdkwid: '', tcdcmpid: '', tcdadid: '', refId: '', platform: '', version: '', skin: '', templateExtra: '', type: 10, extra: 'INDEX' }; D ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.gillmanauto |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.gillmanauto.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:17:44 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 Connection: close P3P: "https://secure4.dealer Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ssoid=63d3063a0a0a00 Content-Type: text/html;charset=iso Set-Cookie: JSESSIONID=16yu4l7go8ukz Set-Cookie: lbpoolmember=3607170570 X-DDC-Arch-Trace: ,HttpResponse,CookieSet Set-Cookie: ddcpoolid=CmsPoolA;path=/ <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms21.dealer.ddc p7070 --> <title>Gillman Acura, Honda, Nissan, Mitsubishi, Chevrolet, Subaru, Chrysler, Jeep, Dodge, GMC, ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /apps/video/player |
GET /apps/video/player Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 200 OK Content-Type: application/x-shockwave ETag: "-5702536121365908084" Accept-Ranges: bytes Last-Modified: Fri, 21 Jan 2011 16:08:17 GMT Content-Length: 137859 Date: Sun, 17 Apr 2011 14:42:01 GMT Server: lighttpd/1.4.10 Set-Cookie: lbpoolmember=3590393354 X-DDC-Arch-Trace: ,HttpResponse CWS ....x...wX...(Z=0d.CF..0. "Q...J..$H.......A..Q.A.. .V..... >.....@.B.... ....q....@`}@PT.Y.`.....@.F^x.0 ...6.. .......8..\......|<..D... ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /shows/slideshows |
GET /shows/slideshows Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:42:11 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.7.1.el5 i386 java/1.5.0_16 Content-Type: text/xml;charset=iso-8859 Set-Cookie: lbpoolmember=1728122378 X-DDC-Arch-Trace: ,HttpResponse Content-Length: 2539 <?xml version="1.0"?><gallery rotate="0"> <image path="http://pictures <image path="http://pictures ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /sites/g/gillmanauto |
GET /sites/g/gillmanauto Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 200 OK Content-Type: application/x-shockwave ETag: "8069559885457818375" Accept-Ranges: bytes Last-Modified: Tue, 23 Nov 2010 21:43:52 GMT Content-Length: 26053 Date: Sun, 17 Apr 2011 14:41:59 GMT Server: lighttpd/1.4.10 Set-Cookie: lbpoolmember=3623947786 X-DDC-Arch-Trace: ,HttpResponse CWS Tx..x...y<...8~.Y.CL.[hd. ...5B.L....E.ii%&&j&.iF. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /v8/templates/139/images |
GET /v8/templates/139/images Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 200 OK Content-Type: image/gif ETag: "7814055884486298376" Accept-Ranges: bytes Last-Modified: Fri, 18 Dec 2009 15:09:05 GMT Content-Length: 373 Date: Sun, 17 Apr 2011 14:41:57 GMT Server: lighttpd/1.4.10 Set-Cookie: lbpoolmember=3623947786 X-DDC-Arch-Trace: ,HttpResponse GIF89a2......S..W....... ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /v8/widgets/generic/image |
GET /v8/widgets/generic/image Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 200 OK Content-Type: application/x-shockwave ETag: "8637866625878465884" Accept-Ranges: bytes Last-Modified: Mon, 27 Dec 2010 19:12:23 GMT Content-Length: 57942 Date: Sun, 17 Apr 2011 14:41:59 GMT Server: lighttpd/1.4.10 Set-Cookie: lbpoolmember=3623947786 X-DDC-Arch-Trace: ,HttpResponse CWS ....x....x...?....h%Y...! ......{...FH.....jUl ..}......3ugg..93;;.... ..K..r.$I...-[6.r.%R[w4.. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.gillmanauto.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:17:44 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 Connection: close P3P: "https://secure4.dealer Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ssoid=63d3063a0a0a00 Content-Type: text/html;charset=iso Set-Cookie: JSESSIONID=16yu4l7go8ukz Set-Cookie: lbpoolmember=3607170570 X-DDC-Arch-Trace: ,HttpResponse,CookieSet Set-Cookie: ddcpoolid=CmsPoolA;path=/ <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms21.dealer.ddc p7070 --> <title>Gillman Acura, Honda, Nissan, Mitsubishi, Chevrolet, Subaru, Chrysler, Jeep, Dodge, GMC, ...[SNIP]... <link rel="shortcut icon" type="image/vnd.microsoft <script type="text/javascript" src="http://static.dealer ...[SNIP]... </script> <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer <script type="text/javascript" src="http://static.dealer ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.gillmanauto |
Path: | /index.htm |
GET /index.htm HTTP/1.1 Host: www.gillmanauto.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:17:44 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.el5 i386 java/1.5.0_16 Connection: close P3P: "https://secure4.dealer Expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: ssoid=63d3063a0a0a00 Content-Type: text/html;charset=iso Set-Cookie: JSESSIONID=16yu4l7go8ukz Set-Cookie: lbpoolmember=3607170570 X-DDC-Arch-Trace: ,HttpResponse,CookieSet Set-Cookie: ddcpoolid=CmsPoolA;path=/ <!DOCTYPE html> <html xmlns="http://www.w3.org <head> <!-- wccms21.dealer.ddc p7070 --> <title>Gillman Acura, Honda, Nissan, Mitsubishi, Chevrolet, Subaru, Chrysler, Jeep, Dodge, GMC, ...[SNIP]... s.getCity(), $account.Address.getState ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.gillmanauto |
Path: | /smartbrowse/ajax/used |
GET /smartbrowse/ajax/used Host: www.gillmanauto.com Proxy-Connection: keep-alive Referer: http://www.gillmanauto X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.204 Safari/534.16 Accept: application/json, text/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ssoid=63e942630a0a00 |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:42:09 GMT Server: Jetty/5.1.1 (Linux/2.6.18-128.7.1.el5 i386 java/1.5.0_16 P3P: "https://secure4.dealer Cache-Control: no-store Content-Type: text/html;charset=iso X-DDC-Arch-Trace: ,HttpResponse Content-Length: 3230 { "SByear" : { "2011":"2011 (17)", "2010":"2010 (97)", "2009":"2009 (88)", "2008":"2008 (187)", "2007":"2007 (116)", "2006":"2006 (68)", "2005":"2005 (44)", "2004":"2004 (40)", "2003":"2003 ...[SNIP]... |