1. Cross-site scripting (reflected)
2. SSL cookie without secure flag set
3. Cookie without HttpOnly flag set
4. HTML does not specify charset
Severity: | High |
Confidence: | Certain |
Host: | https://connect.sungardhe |
Path: | /customer_support/start |
GET /customer_support/start Host: connect.sungardhe.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sun, 02 Jan 2011 14:39:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET content-language: en cache-control: no-cache pragma: no-cache content-type: text/html;charset=UTF-8 content-length: 540 set-cookie: _sn=Y8o9naQNYUqfBJfB <html><body><form action="/customer_support <input type = "hidde ...[SNIP]... <input type = "hidden" name="3d156"><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://connect.sungardhe |
Path: | /customer_support/start |
GET /customer_support/start Host: connect.sungardhe.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sun, 02 Jan 2011 14:38:10 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: no-cache, must-revalidate pragma: no-cache content-language: en cache-control: no-cache pragma: no-cache content-type: text/html;charset=UTF-8 content-length: 581 set-cookie: _sn=81vr7fJb8id45S9T <html><body><form action="/customer_support <input type = "hidden" name="_sn" value="81vr7fJb8id4 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://connect.sungardhe |
Path: | /customer_support/start |
GET /customer_support/start Host: connect.sungardhe.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sun, 02 Jan 2011 14:38:10 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET cache-control: no-cache, must-revalidate pragma: no-cache content-language: en cache-control: no-cache pragma: no-cache content-type: text/html;charset=UTF-8 content-length: 581 set-cookie: _sn=81vr7fJb8id45S9T <html><body><form action="/customer_support <input type = "hidden" name="_sn" value="81vr7fJb8id4 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://connect.sungardhe |
Path: | / |
GET / HTTP/1.1 Host: connect.sungardhe.com Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/html Content-Location: http://connect.sungardhe Last-Modified: Mon, 26 Jul 2010 20:14:38 GMT Accept-Ranges: bytes ETag: "98f9b12cff2ccb1:f02" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sun, 02 Jan 2011 14:41:31 GMT Vary: Accept-Encoding Content-Length: 1451 <HTML> <HEAD> <HEAD> <META HTTP-EQUIV="cache-control <META HTTP-EQUIV="pragma" CONTENT="no-cache"> <META HTTP-EQUIV="expires" CONTENT="Sat, 01 Jan 2000 05:00:00 GMT"> <TITLE ...[SNIP]... |