1. Cross-site scripting (reflected)
1.1. http://business.verizon.net/SMBPortalWeb/appmanager/SMBPortal/smb [REST URL parameter 3]
1.2. http://business.verizon.net/SMBPortalWeb/appmanager/SMBPortal/smb [REST URL parameter 4]
1.3. http://business.verizon.net/SMBPortalWeb/appmanager/SMBPortal/smb [_pageLabel parameter]
Severity: | High |
Confidence: | Firm |
Host: | http://business.verizon |
Path: | /SMBPortalWeb/appmanager |
GET /SMBPortalWeb/appmanager Host: business.verizon.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: amlbcookie=02; state=; product_type=Unknown; op629viss-vobsgum |
HTTP/1.1 404 Not Found Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b Content-Length: 81 X-Powered-By: Servlet/2.5 JSP/2.1 Content-Type: text/html; charset=UTF-8 Expires: Sat, 20 Nov 2010 02:24:40 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 20 Nov 2010 02:24:40 GMT Connection: close Vary: Accept-Encoding Set-Cookie: SaasSessionID=W9dBMn Resource /SMBPortal923dc(a)cae14d5df3e/smb could not be resolved for locale null. |
Severity: | High |
Confidence: | Firm |
Host: | http://business.verizon |
Path: | /SMBPortalWeb/appmanager |
GET /SMBPortalWeb/appmanager Host: business.verizon.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: amlbcookie=02; state=; product_type=Unknown; op629viss-vobsgum |
HTTP/1.1 404 Not Found Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b Content-Length: 81 X-Powered-By: Servlet/2.5 JSP/2.1 Content-Type: text/html; charset=UTF-8 Expires: Sat, 20 Nov 2010 02:24:40 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 20 Nov 2010 02:24:40 GMT Connection: close Vary: Accept-Encoding Set-Cookie: SaasSessionID=p9nBMn Resource /SMBPortal/smbc0137(a)ec58675ea9d could not be resolved for locale null. |
Severity: | High |
Confidence: | Certain |
Host: | http://business.verizon |
Path: | /SMBPortalWeb/appmanager |
GET /SMBPortalWeb/appmanager Host: business.verizon.net Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.517.44 Safari/534.7 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: amlbcookie=02; state=; product_type=Unknown; op629viss-vobsgum |
HTTP/1.1 200 OK Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b X-Powered-By: Servlet/2.5 JSP/2.1 Content-Type: text/html; charset=UTF-8 Expires: Sat, 20 Nov 2010 02:24:40 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 20 Nov 2010 02:24:40 GMT Connection: close Vary: Accept-Encoding Set-Cookie: SaasSessionID=2rdQMn Content-Length: 112563 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><title ...[SNIP]... hHeaderText"); if(searchFlow != null && searchFlow == "Shop") searchBox = document.getElementById( var f_pageDefLabel = 'SMBPortal_page_main if (f_pageDefLabel != "SMBPortal_page_SignIn") searchBox.focus(); } onload = focusIt; // end WR 61703 </script> ...[SNIP]... |