1. Password field with autocomplete enabled
1.1. https://vulnerable.bugzilla.version.3.2.3.host/
1.2. https://vulnerable.bugzilla.version.3.2.3.host/enter_bug.cgi
2. Cross-site scripting (reflected)
3. SSL cookie without secure flag set
4. Cookie without HttpOnly flag set
5.1. https://vulnerable.bugzilla.version.3.2.3.host/createaccount.cgi
5.2. https://vulnerable.bugzilla.version.3.2.3.host/js/field.js
5.3. https://vulnerable.bugzilla.version.3.2.3.host/js/productform.js
5.4. https://vulnerable.bugzilla.version.3.2.3.host/js/util.js
5.5. https://vulnerable.bugzilla.version.3.2.3.host/skins/contrib/Dusk/buglist.css
5.6. https://vulnerable.bugzilla.version.3.2.3.host/skins/contrib/Dusk/global.css
5.7. https://vulnerable.bugzilla.version.3.2.3.host/skins/standard/buglist.css
5.8. https://vulnerable.bugzilla.version.3.2.3.host/skins/standard/global.css
5.9. https://vulnerable.bugzilla.version.3.2.3.host/skins/standard/index.css
7.1. https://vulnerable.bugzilla.version.3.2.3.host/
7.2. https://vulnerable.bugzilla.version.3.2.3.host/attachment.cgi
7.3. https://vulnerable.bugzilla.version.3.2.3.host/buglist.cgi
7.4. https://vulnerable.bugzilla.version.3.2.3.host/createaccount.cgi
7.5. https://vulnerable.bugzilla.version.3.2.3.host/enter_bug.cgi
7.6. https://vulnerable.bugzilla.version.3.2.3.host/report.cgi
7.7. https://vulnerable.bugzilla.version.3.2.3.host/request.cgi
7.8. https://vulnerable.bugzilla.version.3.2.3.host/show_bug.cgi
Severity: | Low |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | / |
GET / HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:35:34 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 8208 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Bugzilla Main Page</title> <link rel="Top" hre ...[SNIP]... </ul><form name="login" action="https://bugs <table id="login-small"> ...[SNIP]... <td> <input type="password" size="20" id="Bugzilla_password" name="Bugzilla_password"> </td> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /enter_bug.cgi |
GET /enter_bug.cgi?product Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:40 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 6244 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Log in to Bugzilla</title> <link rel="Top" hre ...[SNIP]... </p> <form name="login" action="enter_bug.cgi" method="POST"> <table> ...[SNIP]... <td> <input type="password" size="35" id="Bugzilla_password" name="Bugzilla_password"> </td> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /show_bug.cgi |
GET /show_bug.cgi?id=49235 HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:10:02 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 31858 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Bug 49235 – Searching for ...return false. ...[SNIP]... <link rel="Last" href="show_bug.cgi?id ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /buglist.cgi |
GET /buglist.cgi?keywords Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:37 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Content-disposition: inline; filename="bugs-2011-05-24 Set-Cookie: LASTORDER=bugs.bug_status Set-Cookie: BUGLIST=29278%3A49235 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 17709 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Bug List</title> <link rel="Top" href="https:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /buglist.cgi |
GET /buglist.cgi?keywords Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:37 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Content-disposition: inline; filename="bugs-2011-05-24 Set-Cookie: LASTORDER=bugs.bug_status Set-Cookie: BUGLIST=29278%3A49235 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 17709 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Bug List</title> <link rel="Top" href="https:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /createaccount.cgi |
GET /createaccount.cgi HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:37:04 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 5872 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Create a new Bugzilla account</title> <link ...[SNIP]... <a href="mailto:admin@webkit.org">admin@webkit.org</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /js/field.js |
GET /js/field.js HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:41 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Sat, 17 Oct 2009 22:49:31 GMT ETag: "39d8-47629535a34c0" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:02:01 GMT Vary: Accept-Encoding Connection: close Content-Type: application/javascript Content-Length: 14808 /* The contents of this file are subject to the Mozilla Public * License Version 1.1 (the "License"); you may not use this file * except in compliance with the License. You may obtain a copy of * t ...[SNIP]... <mkanat@bugzilla.org> ...[SNIP]... <guy.pyrzak@gmail.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /js/productform.js |
GET /js/productform.js HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:37:14 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Fri, 03 Jul 2009 02:14:27 GMT ETag: "3bd2-46dc3b73b26c0" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:30:34 GMT Vary: Accept-Encoding Connection: close Content-Type: application/javascript Content-Length: 15314 /* The contents of this file are subject to the Mozilla Public * License Version 1.1 (the "License"); you may not use this file * except in compliance with the License. You may obtain a copy of * t ...[SNIP]... <kiko@async.com.br> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /js/util.js |
GET /js/util.js HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:39 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Fri, 03 Jul 2009 02:14:27 GMT ETag: "f3a-46dc3b73b26c0" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:01:59 GMT Vary: Accept-Encoding Connection: close Content-Type: application/javascript Content-Length: 3898 /* ***** BEGIN LICENSE BLOCK ***** * Version: MPL 1.1 * * The contents of this file are subject to the Mozilla Public License Version * 1.1 (the "License"); you may not use this file except in com ...[SNIP]... <mkanat@bugzilla.org> ...[SNIP]... <christopher@aillon.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /skins/contrib/Dusk |
GET /skins/contrib/Dusk Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:49 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Fri, 03 Jul 2009 02:14:27 GMT ETag: "3b3-46dc3b73b26c0" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:02:09 GMT Vary: Accept-Encoding Connection: close Content-Type: text/css Content-Length: 947 /* The contents of this file are subject to the Mozilla Public * License Version 1.1 (the "License"); you may not use this file * except in compliance with the License. You may obtain a copy of ...[SNIP]... <mschrag@pobox.com> ...[SNIP]... <bugzilla@glob.com.au> ...[SNIP]... <wurblzap@gmail.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /skins/contrib/Dusk |
GET /skins/contrib/Dusk Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:41 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Fri, 03 Jul 2009 02:14:27 GMT ETag: "1263-46dc3b73b26c0" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:02:01 GMT Vary: Accept-Encoding Connection: close Content-Type: text/css Content-Length: 4707 /* The contents of this file are subject to the Mozilla Public * License Version 1.1 (the "License"); you may not use this file * except in compliance with the License. You may obtain a copy of ...[SNIP]... <mschrag@pobox.com> ...[SNIP]... <bugzilla@glob.com.au> ...[SNIP]... <wurblzap@gmail.com> ...[SNIP]... <LpSolit@gmail.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /skins/standard/buglist |
GET /skins/standard/buglist Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:45 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Fri, 03 Jul 2009 02:14:27 GMT ETag: "6fb-46dc3b73b26c0" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:02:05 GMT Vary: Accept-Encoding Connection: close Content-Type: text/css Content-Length: 1787 /* The contents of this file are subject to the Mozilla Public * License Version 1.1 (the "License"); you may not use this file * except in compliance with the License. You may obtain a copy of ...[SNIP]... <myk@mozilla.org> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /skins/standard/global |
GET /skins/standard/global Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:38 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Fri, 03 Jul 2009 02:14:27 GMT ETag: "20dc-46dc3b73b26c0" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:01:58 GMT Vary: Accept-Encoding Connection: close Content-Type: text/css Content-Length: 8412 /* The contents of this file are subject to the Mozilla Public * License Version 1.1 (the "License"); you may not use this file * except in compliance with the License. You may obtain a copy of ...[SNIP]... <bugzilla@glob.com.au> ...[SNIP]... <kiko@async.com.br> ...[SNIP]... <vitaly@rathedg.com> ...[SNIP]... <light@rathedg.com> ...[SNIP]... <wurblzap@gmail.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /skins/standard/index.css |
GET /skins/standard/index.css HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:35:36 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Fri, 03 Jul 2009 02:13:45 GMT ETag: "6b6-46dc3b4ba4840" Accept-Ranges: bytes Cache-Control: max-age=32000000 Expires: Tue, 29 May 2012 10:28:56 GMT Vary: Accept-Encoding Connection: close Content-Type: text/css Content-Length: 1718 /* The contents of this file are subject to the Mozilla Public * License Version 1.1 (the "License"); you may not use this file * except in compliance with the License. You may obtain a copy of ...[SNIP]... <vitaly@rathedg.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /buglist.cgi |
GET /robots.txt HTTP/1.0 Host: vulnerable.bugzilla.version.3.2.3.host |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:39 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Last-Modified: Wed, 06 Feb 2008 22:40:55 GMT ETag: "2c-445850cd38bc0" Accept-Ranges: bytes Content-Length: 44 Vary: Accept-Encoding Connection: close Content-Type: text/plain User-agent: * Allow: /index.cgi Disallow: / |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | / |
GET / HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:35:34 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 8208 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Bugzilla Main Page</title> <link rel="Top" hre ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /attachment.cgi |
GET /attachment.cgi?id=73356 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:09:37 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 16566 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Attachment 73356 Details for Bug 49235</title ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /buglist.cgi |
GET /buglist.cgi?keywords Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:37 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Content-disposition: inline; filename="bugs-2011-05-24 Set-Cookie: LASTORDER=bugs.bug_status Set-Cookie: BUGLIST=29278%3A49235 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 17709 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Bug List</title> <link rel="Top" href="https:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /createaccount.cgi |
GET /createaccount.cgi HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:37:04 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 5872 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Create a new Bugzilla account</title> <link ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /enter_bug.cgi |
GET /enter_bug.cgi?product Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:08:40 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 6244 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Log in to Bugzilla</title> <link rel="Top" hre ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /report.cgi |
GET /report.cgi HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:37:09 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 5485 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Reporting and Charting Kitchen</title> <link r ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /request.cgi |
GET /request.cgi HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:37:11 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10559 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Request Queue</title> <link rel="Top" href="ht ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | /show_bug.cgi |
GET /show_bug.cgi?id=49235 HTTP/1.1 Host: vulnerable.bugzilla.version.3.2.3.host Connection: keep-alive Referer: https://vulnerable.bugzilla.version.3.2.3.host User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: LASTORDER=bugs.bug_status |
HTTP/1.1 200 OK Date: Wed, 25 May 2011 01:09:26 GMT Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c DAV/2 mod_python/3.3.1 Python/2.6.6 PHP/5.2.17 Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 31729 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>Bug 49235 – Searching for ...return false. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://vulnerable.bugzilla.version.3.2.3.host |
Path: | / |
Issued to: | *.webkit.org |
Issued by: | Entrust Certification Authority - L1C |
Valid from: | Mon Jan 31 17:14:55 CST 2011 |
Valid to: | Tue Jan 29 03:39:19 CST 2013 |
Issued to: | Entrust Certification Authority - L1C |
Issued by: | Entrust.net Certification Authority (2048) |
Valid from: | Thu Dec 10 14:43:54 CST 2009 |
Valid to: | Tue Dec 10 15:13:54 CST 2019 |
Issued to: | Entrust.net Certification Authority (2048) |
Issued by: | Entrust.net Certification Authority (2048) |
Valid from: | Fri Dec 24 11:50:51 CST 1999 |
Valid to: | Tue Jul 24 09:15:12 CDT 2029 |