1. Cross-site scripting (reflected)
2. Cleartext submission of password
3. Password field with autocomplete enabled
4. Cookie scoped to parent domain
4.1. http://www.wikia.com/__spotlights/lg.php
4.2. http://www.wikia.com/__spotlights/spc.php
5. Cross-domain Referer leakage
6. Cross-domain script include
7. Cookie without HttpOnly flag set
7.2. http://www.wikia.com/Wikia
7.3. http://www.wikia.com/__spotlights/lg.php
7.4. http://www.wikia.com/__spotlights/spc.php
7.5. http://www.wikia.com/index.php
8. Content type incorrectly stated
8.1. http://www.wikia.com/index.php
8.2. http://www.wikia.com/opensearch_desc.php
Severity: | High |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /index.php |
GET /index.php?action=ajax&rs Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com X-Requested-With: XMLHttpRequest Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 500 Internal Server Error Server: Varnish Retry-After: 0 X-Selected-Backend: iowa_apache X-Restarts: 4 Content-Length: 543 Date: Mon, 14 Feb 2011 01:28:08 GMT Connection: close X-Served-By: varnish-v12-ASH X-Cache: MISS X-Cache-Hits: 0 X-Timer: S1297646887.207281351,VS0 Set-Cookie: Geo = {"city":"Dallas","country X-Age: 2 X-Varnish-Config: $Revision: 19021 $ <html> <head> <title> www.wikia.com/index.php <script sr ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /Wikia |
GET /Wikia HTTP/1.1 Host: www.wikia.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Content-language: en Last-Modified: Mon, 14 Feb 2011 00:14:48 GMT Content-Type: text/html; charset=utf-8 X-Cacheable: YES Date: Mon, 14 Feb 2011 01:26:21 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 19, 31 X-Timer: S1297646781.670613527,VS0 Vary: Accept-Encoding,Cookie X-Age: 1698 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646781 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 38557 <!doctype html> <html lang="en" dir="ltr"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=1200"> <meta name="description" content="W ...[SNIP]... </div> <form action="" method="post" name="userajaxloginform" id="userajaxloginformhide <input type="text" name="wpName" id="wpName1Ajax" tabindex="101" size="20" /> <input type="password" name="wpPassword" id="wpPassword1Ajax" tabindex="102" size="20" /> <input type="checkbox" name="wpRemember" id="wpRemember1Ajax" tabindex="104" value="1" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /Wikia |
GET /Wikia HTTP/1.1 Host: www.wikia.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Content-language: en Last-Modified: Mon, 14 Feb 2011 00:14:48 GMT Content-Type: text/html; charset=utf-8 X-Cacheable: YES Date: Mon, 14 Feb 2011 01:26:21 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 19, 31 X-Timer: S1297646781.670613527,VS0 Vary: Accept-Encoding,Cookie X-Age: 1698 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646781 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 38557 <!doctype html> <html lang="en" dir="ltr"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=1200"> <meta name="description" content="W ...[SNIP]... </div> <form action="" method="post" name="userajaxloginform" id="userajaxloginformhide <input type="text" name="wpName" id="wpName1Ajax" tabindex="101" size="20" /> <input type="password" name="wpPassword" id="wpPassword1Ajax" tabindex="102" size="20" /> <input type="checkbox" name="wpRemember" id="wpRemember1Ajax" tabindex="104" value="1" /> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /__spotlights/lg.php |
GET /__spotlights/lg.php Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Pragma: no-cache P3P: CP="CUR ADM OUR NOR STA NID" Set-Cookie: OAID=ef5275f8036c435 Content-Type: image/gif X-Cacheable: NO:Cache-Control=private Content-Length: 43 Date: Mon, 14 Feb 2011 01:22:47 GMT Connection: keep-alive X-Served-By: varnish-v11-ASH X-Cache: MISS X-Cache-Hits: 0 X-Timer: S1297646567.179046154,VS0 X-Age: 0 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate GIF89a.............!..... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /__spotlights/spc.php |
GET /__spotlights/spc.php Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com X-Requested-With: XMLHttpRequest Accept: text/javascript, application/javascript, */*; q=0.01 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Pragma: no-cache P3P: CP="CUR ADM OUR NOR STA NID" Set-Cookie: OAGEO=US%7CTX%7CDallas Set-Cookie: OAID=2d492e32b2be365 Content-Size: 7613 Content-Type: application/x-javascript; charset=UTF-8 X-Cacheable: YES - FORCED Date: Mon, 14 Feb 2011 01:26:26 GMT Connection: keep-alive X-Served-By: varnish-v11-ASH X-Cache: MISS X-Cache-Hits: 0 X-Timer: S1297646786.671192646,VS0 Vary: Accept-Encoding X-Age: 0 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 7613 var OA_output = new Array(); OA_output['14'] = ''; OA_output['14'] += "<"+"a href=\'/__spotlights/ck ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /index.php |
GET /index.php?action=ajax&rs Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com X-Requested-With: XMLHttpRequest Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Status: 200 OK Last-Modified: Mon, 14 Feb 2011 01:14:08 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 X-Cacheable: YES - FORCED Date: Mon, 14 Feb 2011 01:26:35 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 11, 57 X-Timer: S1297646795.460254908,VS0 Vary: Accept-Encoding X-Age: 478 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646795 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 1391 <section class="WikiaActivity <h1 class="activity-heading" <ul> <li> <img src="http://images1.wikia <em> ...[SNIP]... <li> <img src="http://images1.wikia <em> ...[SNIP]... <li> <img src="http://images1.wikia <em> ...[SNIP]... <li> <img src="http://images1.wikia <em> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /Wikia |
GET /Wikia HTTP/1.1 Host: www.wikia.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Content-language: en Last-Modified: Mon, 14 Feb 2011 00:14:48 GMT Content-Type: text/html; charset=utf-8 X-Cacheable: YES Date: Mon, 14 Feb 2011 01:26:21 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 19, 31 X-Timer: S1297646781.670613527,VS0 Vary: Accept-Encoding,Cookie X-Age: 1698 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646781 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 38557 <!doctype html> <html lang="en" dir="ltr"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=1200"> <meta name="description" content="W ...[SNIP]... <!-- Start for GA_Urchin, page_view --> <script type="text/javascript" src="http://www.google ...[SNIP]... <!-- Start for QuantServe, page_view --> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | / |
GET / HTTP/1.1 Host: www.wikia.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 301 Moved Permanently Server: Apache Last-Modified: Mon, 14 Feb 2011 00:49:13 GMT Location: http://www.wikia.com Content-Type: text/html; charset=utf-8 X-Cacheable: YES Date: Mon, 14 Feb 2011 01:22:35 GMT Connection: keep-alive X-Served-By: varnish-s1-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 8, 12 X-Timer: S1297646555.288983345,VS0 Vary: Accept-Encoding,Cookie Set-Cookie: Geo = {"city":"Dallas","country X-Age: 1161 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646555 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /Wikia |
GET /Wikia HTTP/1.1 Host: www.wikia.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Content-language: en Last-Modified: Mon, 14 Feb 2011 00:14:48 GMT Content-Type: text/html; charset=utf-8 X-Cacheable: YES Date: Mon, 14 Feb 2011 01:26:21 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 19, 31 X-Timer: S1297646781.670613527,VS0 Vary: Accept-Encoding,Cookie X-Age: 1698 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646781 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 38557 <!doctype html> <html lang="en" dir="ltr"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=1200"> <meta name="description" content="W ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /__spotlights/lg.php |
GET /__spotlights/lg.php Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Pragma: no-cache P3P: CP="CUR ADM OUR NOR STA NID" Set-Cookie: OAID=ef5275f8036c435 Content-Type: image/gif X-Cacheable: NO:Cache-Control=private Content-Length: 43 Date: Mon, 14 Feb 2011 01:22:47 GMT Connection: keep-alive X-Served-By: varnish-v11-ASH X-Cache: MISS X-Cache-Hits: 0 X-Timer: S1297646567.179046154,VS0 X-Age: 0 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate GIF89a.............!..... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /__spotlights/spc.php |
GET /__spotlights/spc.php Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com X-Requested-With: XMLHttpRequest Accept: text/javascript, application/javascript, */*; q=0.01 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Pragma: no-cache P3P: CP="CUR ADM OUR NOR STA NID" Set-Cookie: OAGEO=US%7CTX%7CDallas Set-Cookie: OAID=2d492e32b2be365 Content-Size: 7613 Content-Type: application/x-javascript; charset=UTF-8 X-Cacheable: YES - FORCED Date: Mon, 14 Feb 2011 01:26:26 GMT Connection: keep-alive X-Served-By: varnish-v11-ASH X-Cache: MISS X-Cache-Hits: 0 X-Timer: S1297646786.671192646,VS0 Vary: Accept-Encoding X-Age: 0 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 7613 var OA_output = new Array(); OA_output['14'] = ''; OA_output['14'] += "<"+"a href=\'/__spotlights/ck ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.wikia.com |
Path: | /index.php |
GET /index.php?action=ajax&rs Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com X-Requested-With: XMLHttpRequest Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Status: 200 OK Last-Modified: Mon, 14 Feb 2011 01:14:08 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 X-Cacheable: YES - FORCED Date: Mon, 14 Feb 2011 01:26:35 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 11, 57 X-Timer: S1297646795.460254908,VS0 Vary: Accept-Encoding X-Age: 478 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646795 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 1391 <section class="WikiaActivity <h1 class="activity-heading" <ul> <li> <img src="http://images1.wikia ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.wikia.com |
Path: | /index.php |
GET /index.php?action=ajax&rs Host: www.wikia.com Proxy-Connection: keep-alive Referer: http://www.wikia.com X-Requested-With: XMLHttpRequest Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache Status: 200 OK Last-Modified: Mon, 14 Feb 2011 01:14:08 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 X-Cacheable: YES - FORCED Date: Mon, 14 Feb 2011 01:26:35 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 11, 57 X-Timer: S1297646795.460254908,VS0 Vary: Accept-Encoding X-Age: 478 Set-Cookie: varnish-stat=/server/ASH Set-Cookie: loadtime=S1297646795 X-Varnish-Config: $Revision: 19021 $ Cache-Control: private, s-maxage=0, max-age=0, must-revalidate Content-Length: 1391 <section class="WikiaActivity <h1 class="activity-heading" <ul> <li> <img src="http://images1.wikia ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.wikia.com |
Path: | /opensearch_desc.php |
GET /opensearch_desc.php HTTP/1.1 Host: www.wikia.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: Geo={"city":"Dallas", |
HTTP/1.1 200 OK Server: Apache X-Pass-Expires: Sun, 13 Feb 2011 07:21:52 GMT X-Pass-Cache-Control: max-age=86400 Content-Type: application/opensear X-Cacheable: YES Date: Mon, 14 Feb 2011 01:26:37 GMT Connection: keep-alive X-Served-By: varnish-s3-SJC, varnish-v11-ASH X-Cache: HIT, HIT X-Cache-Hits: 547, 593 X-Timer: S1297646797.319349527,VS0 Vary: Accept-Encoding X-Age: 69189 X-Varnish-Config: $Revision: 19021 $ Cache-Control: max-age=86400 Content-Length: 706 <?xml version="1.0"?> ...[SNIP]... |