1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://www.favlog.de |
Path: | /submit.php |
GET /submit.php4b394"%20style%3dx Host: www.favlog.de Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:15:17 GMT Server: Apache/2.2.11 (Unix) DAV/2 mod_ssl/2.2.11 OpenSSL/0.9.8k mod_jk/1.2.26 PHP/5.2.9 mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.10.0 X-Powered-By: PHP/5.2.9 Set-Cookie: PHPSESSID=9ccdeh3nqm Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 18450 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html dir="ltr" xmlns="http://www.w3.org ...[SNIP]... <a href="/upcoming/submit ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.favlog.de |
Path: | /submit.php |
GET /submit.php HTTP/1.1 Host: www.favlog.de Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Found Date: Sun, 17 Apr 2011 14:14:48 GMT Server: Apache/2.2.11 (Unix) DAV/2 mod_ssl/2.2.11 OpenSSL/0.9.8k mod_jk/1.2.26 PHP/5.2.9 mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.10.0 X-Powered-By: PHP/5.2.9 Set-Cookie: PHPSESSID=1krk4g9csi Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Location: /login.php?return=/submit Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8 |