1. Cross-site scripting (reflected)
1.1. http://www.webbyawards.com/webbys/current_honorees.php [media_id parameter]
1.2. http://www.webbyawards.com/webbys/current_honorees.php [season parameter]
2. Cookie without HttpOnly flag set
4. Cross-domain Referer leakage
5. Cross-domain script include
5.1. http://www.webbyawards.com/nettedsplashpage/nettedsignup.html
5.2. http://www.webbyawards.com/webbys/current_honorees.php
6.1. http://www.webbyawards.com/nettedsplashpage/scripts/jquery.cookie.js
6.2. http://www.webbyawards.com/script/site_globals.js
7. Content type incorrectly stated
7.1. http://www.webbyawards.com/script/rotate_quote.js
7.2. http://www.webbyawards.com/script/site_globals.js
Severity: | High |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /webbys/current_honorees |
GET /webbys/current_honorees Host: www.webbyawards.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:24:49 GMT Server: Apache X-Powered-By: PHP/4.3.10 Set-Cookie: PHPSESSID=5fff8524ae Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 20661 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <input type="hidden" name="media_id" value="96f9e24"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /webbys/current_honorees |
GET /webbys/current_honorees Host: www.webbyawards.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:24:53 GMT Server: Apache X-Powered-By: PHP/4.3.10 Set-Cookie: PHPSESSID=4dcb5dc8d0 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 21356 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <a href="current_honorees ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.webbyawards |
Path: | /webbys/current_honorees |
GET /webbys/current_honorees Host: www.webbyawards.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:24:27 GMT Server: Apache X-Powered-By: PHP/4.3.10 Set-Cookie: PHPSESSID=fba7577a5b Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 26238 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /webbys/current_honorees |
GET /webbys/current_honorees Host: www.webbyawards.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:24:27 GMT Server: Apache X-Powered-By: PHP/4.3.10 Set-Cookie: PHPSESSID=fba7577a5b Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 26238 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <div id="mc_embed_signup" style="width: 170px;"> <form action="http://webby <!-- <fieldset style="-moz-border-radius ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /webbys/current_honorees |
GET /webbys/current_honorees Host: www.webbyawards.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:24:29 GMT Server: Apache X-Powered-By: PHP/4.3.10 Set-Cookie: PHPSESSID=50e7571677 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 26416 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... </script> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="http://ajax ...[SNIP]... <br /> <a href="http://bx ...[SNIP]... <br /> <a href="http://www ...[SNIP]... <br /> <a href="http://www.legacy ...[SNIP]... <br /> <a href="http://www ...[SNIP]... <br /> <a href="http://www ...[SNIP]... <br /> <a href="http://www.ning.com ...[SNIP]... <br /> <a href="http://www.raptr ...[SNIP]... <br /> <a href="http://en.sevenload ...[SNIP]... <br /> <a href="http://www ...[SNIP]... <br /> <a href="http://www ...[SNIP]... <br /> <a href="http://www ...[SNIP]... </h3> <a href="http://www.twitter <a href="http://www.flickr <a href="http://www.youtube <a href="http://www.webbys ...[SNIP]... </p> <iframe src="http://www.facebook ...[SNIP]... </h3> <a href="http://www.netted ...[SNIP]... <br> <a href="http://www.netted ...[SNIP]... <p><a href="http://www ...[SNIP]... <li><a href="http://iadas.net" target="_blank"><acronym title="The International Academy of Digital Arts and Sciences"> ...[SNIP]... <li><a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /nettedsplashpage |
GET /nettedsplashpage Host: www.webbyawards.com Proxy-Connection: keep-alive Referer: http://www.webbyawards Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=c5911349e5 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:28:43 GMT Server: Apache Last-Modified: Fri, 11 Feb 2011 21:11:18 GMT ETag: "1dac0de-d3f-239ce980" Accept-Ranges: bytes Content-Length: 3391 Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <link rel="stylesheet" type="text/css" href="./css/nettedsignup <script type="text/javascript" src="http://ajax ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /webbys/current_honorees |
GET /webbys/current_honorees Host: www.webbyawards.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:24:27 GMT Server: Apache X-Powered-By: PHP/4.3.10 Set-Cookie: PHPSESSID=fba7577a5b Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 26238 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... </script> <script type="text/javascript" src="http://ajax <script type="text/javascript" src="http://ajax ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /nettedsplashpage/scripts |
GET /nettedsplashpage/scripts Host: www.webbyawards.com Proxy-Connection: keep-alive Referer: http://www.webbyawards Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=c5911349e5 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:28:12 GMT Server: Apache Last-Modified: Mon, 07 Feb 2011 19:06:27 GMT ETag: "dcc0d8-e80-edbfd2c0" Accept-Ranges: bytes Content-Length: 3712 Content-Type: application/x-javascript /*jslint browser: true */ /*global jQuery: true */ /** * jQuery Cookie plugin * * Copyright (c) 2010 Klaus Hartl (stilbuero.de) * Dual licensed under the MIT and GPL licenses: * http://www.opens ...[SNIP]... kie will be set and the cookie transmission will * require a secure protocol (like HTTPS). * @type undefined * * @name $.cookie * @cat Plugins/Cookie * @author Klaus Hartl/klaus.hartl@stilbuero.de */ /** * Get the value of a cookie with the given key. * * @example $.cookie('the_cookie'); * @desc Get the value of a cookie. * * @param String key The key of the cookie. * @return The value of the cookie. * @type String * * @name $.cookie * @cat Plugins/Cookie * @author Klaus Hartl/klaus.hartl@stilbuero.de */ jQuery.cookie = function (key, value, options) { // key and at least value given, set cookie... if (arguments.length > ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.webbyawards |
Path: | /script/site_globals.js |
GET /script/site_globals.js HTTP/1.1 Host: www.webbyawards.com Proxy-Connection: keep-alive Referer: http://www.webbyawards Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=c5911349e5 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:28:11 GMT Server: Apache Last-Modified: Tue, 10 Apr 2007 08:07:30 GMT ETag: "2316053-41b-a52b7480" Accept-Ranges: bytes Content-Length: 1051 Content-Type: application/x-javascript <!-- Begin site global js block --> <!-- function clearTextFields(input) { if (input.value == 'E-mail Address') { input.value = ''; } } function isEmailAddr(email) { var result = false; ...[SNIP]... enter a value for the \"email\" field."); theForm.email.focus(); return (false); } if (!isEmailAddr(theForm { alert("Please enter a complete email address in the form: yourname@yourdomain.com"); theForm.email.focus(); return (false); } if (theForm.email.value { alert("Please enter at least 3 characters in the \"email\" field."); theForm.email.focus(); ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.webbyawards |
Path: | /script/rotate_quote.js |
GET /script/rotate_quote.js HTTP/1.1 Host: www.webbyawards.com Proxy-Connection: keep-alive Referer: http://www.webbyawards Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=c5911349e5 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:28:11 GMT Server: Apache Last-Modified: Wed, 31 Mar 2010 20:36:51 GMT ETag: "2316054-686-b4b71ec0" Accept-Ranges: bytes Content-Length: 1670 Content-Type: application/x-javascript <!-- Begin rotating quote block --> <!-- var quote_text = new Array(); // List of quotes to load. // If adding new items, follow the format used below. quote_text[quote_text ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.webbyawards |
Path: | /script/site_globals.js |
GET /script/site_globals.js HTTP/1.1 Host: www.webbyawards.com Proxy-Connection: keep-alive Referer: http://www.webbyawards Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=c5911349e5 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 01:28:11 GMT Server: Apache Last-Modified: Tue, 10 Apr 2007 08:07:30 GMT ETag: "2316053-41b-a52b7480" Accept-Ranges: bytes Content-Length: 1051 Content-Type: application/x-javascript <!-- Begin site global js block --> <!-- function clearTextFields(input) { if (input.value == 'E-mail Address') { input.value = ''; } } function isEmailAddr(email) { var result = false; ...[SNIP]... |