1. Cross-site scripting (reflected)
1.1. http://www.xulonpress.com/zipdata_lead_form/lead_form.php [Referer HTTP header]
1.2. http://www.xulonpress.com/zipdata_lead_form/lead_form.php [lead_sourceCookie cookie]
2. Cookie without HttpOnly flag set
4. Cross-domain Referer leakage
6. HTML does not specify charset
6.1. http://www.xulonpress.com/imgs/Flash/newvideo6/inc.xulonvideo_home.php
6.2. http://www.xulonpress.com/zipdata_lead_form/lead_form.php
7. Content type incorrectly stated
Severity: | Low |
Confidence: | Certain |
Host: | http://www.xulonpress.com |
Path: | /zipdata_lead_form/lead |
GET /zipdata_lead_form/lead Host: www.xulonpress.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:51:00 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 5830 Connection: close Content-Type: text/html <html> <head> <meta http-equiv='X-UA <style> body table, ul, li, p, h2, a { font-family: Verdana, Arial, Helvetica, sans-serif; font-size: x-small; } td { display:table- ...[SNIP]... <input type='hidden' name='Page_Source' value='http://www.google ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.xulonpress.com |
Path: | /zipdata_lead_form/lead |
GET /zipdata_lead_form/lead Host: www.xulonpress.com Proxy-Connection: keep-alive Referer: http://www.xulonpress.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:52 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 5893 Connection: close Content-Type: text/html <html> <head> <meta http-equiv='X-UA <style> body table, ul, li, p, h2, a { font-family: Verdana, Arial, Helvetica, sans-serif; font-size: x-small; } td { display:table- ...[SNIP]... <input type='hidden' name='lead_source' value="Google_PPC ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.xulonpress.com |
Path: | /index.php |
GET /index.php?lead_source Host: www.xulonpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:11 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Set-Cookie: PHPSESSID=9b582qjcpp Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: refererCookie=deleted; expires=Tue, 16-Mar-2010 18:50:10 GMT Set-Cookie: lead_sourceCookie=Google Connection: close Content-Type: text/html Content-Length: 22985 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Self Publishing - Xulon Press Christian Self Publis ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.xulonpress.com |
Path: | /zipdata_lead_form/lead |
GET /zipdata_lead_form/lead Host: www.xulonpress.com Proxy-Connection: keep-alive Referer: http://www.xulonpress.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:15 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 5850 Connection: close Content-Type: text/html <html> <head> <meta http-equiv='X-UA <style> body table, ul, li, p, h2, a { font-family: Verdana, Arial, Helvetica, sans-serif; font-size: x-small; } td { display:table- ...[SNIP]... <input type='hidden' name='Page_Source' value='http://www.xulonpress.com </td></tr> <tr><td colspan=2><img src='/images/spacer.gif' width=1 height=4 /><br /></td></tr> <tr><td colspan="2" align="center"> <input type="image" src="lead_form_btn.png" alt="Submit button"> </td> </tr> <tr><td colspan=2> <br /><br /><br /></td></tr> </table> </form> <script language="JavaScript" type="text/javascript"> var frmvalidator = new Validator("Leads"); frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali </script> </td></tr></table> </body> </html> |
GET /zipdata_lead_form/lead Host: www.xulonpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:38 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 5750 Connection: close Content-Type: text/html <html> <head> <meta http-equiv='X-UA <style> body table, ul, li, p, h2, a { font-family: Verdana, Arial, Helvetica, sans-serif; font-size: x-small; } td { display:table- ...[SNIP]... <input type='hidden' name='Page_Source' value=''> </td></tr> <tr><td colspan=2><img src='/images/spacer.gif' width=1 height=4 /><br /></td></tr> <tr><td colspan="2" align="center"> <input type="image" src="lead_form_btn.png" alt="Submit button"> </td> </tr> <tr><td colspan=2> <br /><br /><br /></td></tr> </table> </form> <script language="JavaScript" type="text/javascript"> var frmvalidator = new Validator("Leads"); frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali frmvalidator.addVali </script> </td></tr></table> </body> </html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.xulonpress.com |
Path: | /index.php |
GET /index.php?lead_source Host: www.xulonpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:11 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Set-Cookie: PHPSESSID=9b582qjcpp Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: refererCookie=deleted; expires=Tue, 16-Mar-2010 18:50:10 GMT Set-Cookie: lead_sourceCookie=Google Connection: close Content-Type: text/html Content-Length: 22985 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Self Publishing - Xulon Press Christian Self Publis ...[SNIP]... <li><a href="http://www ...[SNIP]... <p style="text-align:left ...[SNIP]... <td align="left" valign="top"><a href="http://www.facebook ...[SNIP]... <td align="left" valign="top"><a href="http://www.youtube ...[SNIP]... <td align="left" valign="top"><a href="http://twitter.com ...[SNIP]... <br />To listen to a Salem radio station near you, <a href="http://www.salem.cc ...[SNIP]... <map name="MapMap2"> <area shape="rect" coords="-5,7,135,54" href="http://www <area shape="rect" coords="282,7,425,52" href="http://www <area shape="rect" coords="142,6,272,53" href="http://www.oneplace <area shape="rect" coords="434,7,563,52" href="http://www <area shape="rect" coords="575,8,698,51" href="http://www <area shape="rect" coords="146,62,287,106" href="http://www <area shape="rect" coords="294,62,390,104" href="http://www <area shape="rect" coords="11,63,142,108" href="http://www <area shape="rect" coords="540,64,623,105" href="http://www <area shape="rect" coords="397,64,533,108" href="http://www <area shape="rect" coords="628,61,691,108" href="http://www.TheFish </map> ...[SNIP]... <map name="SocialMap"> <area shape="rect" coords="55,85,125,140" href="http://www.facebook <area shape="rect" coords="137,87,205,143" href="http://www.youtube </map> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.xulonpress.com |
Path: | /assets/js/gen_valid |
GET /assets/js/gen_valid Host: www.xulonpress.com Proxy-Connection: keep-alive Referer: http://www.xulonpress.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:16 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Tue, 25 May 2010 15:44:45 GMT ETag: "2d70032-471f-4876d0 Accept-Ranges: bytes Content-Length: 18207 Connection: close Content-Type: application/x-javascript /* ------------------------- JavaScript Form Validator (gen_validatorv31.js) Version 3.1 Copyright (C) 2003-2008 JavaScript-Cod ...[SNIP]... tion script is distributed free from JavaScript-Coder.com For updates, please visit: http://www.javascript Questions & comments please send to support@javascript-coder ------------------------- */ function Validator(frmname) { this.formobj=document if(!this.formobj) { alert("Error: couldnot g ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.xulonpress.com |
Path: | /imgs/Flash/newvideo6/inc |
GET /imgs/Flash/newvideo6/inc Host: www.xulonpress.com Proxy-Connection: keep-alive Referer: http://www.xulonpress.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:15 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Set-Cookie: videoCookie=1; expires=Wed, 23-Mar-2011 18:50:15 GMT Content-Length: 1862 Connection: close Content-Type: text/html <html> <head> <script language="javascript">AC <script src="AC_RunActiveContent <script src="/flashdetect/flash ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.xulonpress.com |
Path: | /zipdata_lead_form/lead |
GET /zipdata_lead_form/lead Host: www.xulonpress.com Proxy-Connection: keep-alive Referer: http://www.xulonpress.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:15 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.2.17 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Length: 5850 Connection: close Content-Type: text/html <html> <head> <meta http-equiv='X-UA <style> body table, ul, li, p, h2, a { font-family: Verdana, Arial, Helvetica, sans-serif; font-size: x-small; } td { display:table- ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.xulonpress.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.xulonpress.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=633mndt3md |
HTTP/1.1 200 OK Date: Wed, 16 Mar 2011 18:50:24 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Mon, 09 Mar 2009 21:20:28 GMT ETag: "2b3879b-37e-464b634 Accept-Ranges: bytes Content-Length: 894 Connection: close Content-Type: text/plain ..............h.......(.. ...[SNIP]... |