1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://ca.wiley.com |
Path: | /WileyCDA/WileyTitle |
GET /WileyCDA/WileyTitle Host: ca.wiley.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: wiley.com.SPA.isCoun |
HTTP/1.0 404 Not Found Date: Fri, 07 Jan 2011 21:56:38 GMT Server: Apache Set-Cookie: JSESSIONID=D3C9AA2B8 Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=ISO <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR <html> <head> <link href="http://media.wiley ...[SNIP]... <i>/WileyCDA/WileyTitle ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ca.wiley.com |
Path: | /WileyCDA/WileyTitle |
GET /WileyCDA/WileyTitle Host: ca.wiley.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.0 302 Moved Temporarily Date: Fri, 07 Jan 2011 19:02:03 GMT Server: Apache X-Powered-By: SPA Set-Cookie: wiley.com.SPA.country=US; Domain=.wiley.com; Path=/ Set-Cookie: wiley.com.SPA.isCoun Set-Cookie: wiley.com.SPA.isPreL Location: http://www.wiley.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=ISO-8859-1 |
Severity: | Information |
Confidence: | Certain |
Host: | http://ca.wiley.com |
Path: | /WileyCDA/WileyTitle |
GET /WileyCDA/WileyTitle Host: ca.wiley.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.0 302 Moved Temporarily Date: Fri, 07 Jan 2011 19:02:03 GMT Server: Apache X-Powered-By: SPA Set-Cookie: wiley.com.SPA.country=US; Domain=.wiley.com; Path=/ Set-Cookie: wiley.com.SPA.isCoun Set-Cookie: wiley.com.SPA.isPreL Location: http://www.wiley.com Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=ISO-8859-1 |