1. Cross-site scripting (reflected)
1.1. http://www.couche-tard.com/corporatif/javascript/openwindow.php [REST URL parameter 1]
1.2. http://www.couche-tard.com/corporatif/javascript/openwindow.php [REST URL parameter 2]
1.3. http://www.couche-tard.com/corporatif/javascript/openwindow.php [REST URL parameter 3]
2. Cross-domain Referer leakage
3. Cross-domain script include
4. Cookie without HttpOnly flag set
4.1. http://www.couche-tard.com/corporatif/index.php
4.2. http://www.couche-tard.com/fr/accueil/404custom.aspx
5.1. http://www.couche-tard.com/corporatif/includes_axial/jscalendar/calendar.js
5.2. http://www.couche-tard.com/corporatif/includes_axial/jscalendar/lang/calendar-en.js
6. HTML does not specify charset
7. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/javascript |
GET /corporatif4076a%2522%253e Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: _lang=eng; POSTNUKESID=k6s9usn3 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: cookie_axis_stat=04daa7f7 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:24:10 GMT Content-Length: 79342 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="head ...[SNIP]... <form name="Afficher" method="post" action="/fr/accueil ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/javascript |
GET /corporatif/javascript9dabe%2522%253e Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: _lang=eng; POSTNUKESID=k6s9usn3 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: cookie_axis_stat=04daa7f7 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:24:19 GMT Content-Length: 79342 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="head ...[SNIP]... <form name="Afficher" method="post" action="/fr/accueil ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/javascript |
GET /corporatif/javascript Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: _lang=eng; POSTNUKESID=k6s9usn3 |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: cookie_axis_stat=04daa7f7 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:24:27 GMT Content-Length: 79342 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="head ...[SNIP]... <form name="Afficher" method="post" action="/fr/accueil ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /fr/accueil/404custom |
GET /fr/accueil/404custom Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: UniteRechercheAvancee |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: cookie_axis_stat=04daa7f7 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:24:49 GMT Content-Length: 79265 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="head ...[SNIP]... <form name="Afficher" method="post" action="/fr/accueil ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/index.php |
GET /corporatif/index.php Accept: */* Referer: http://en.wikipedia.org Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Cache-Control: cache Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.13 Set-Cookie: POSTNUKESID=k6s9usn3 Set-Cookie: _lang=eng; expires=Thu, 16-Dec-2010 23:22:44 GMT X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:44 GMT Connection: close Content-Length: 21922 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"> <title>Couche-Tard | Home</title> <link rel="S ...[SNIP]... <br /> <a target="_blank" href="http://tmx ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /fr/accueil/404custom |
GET /fr/accueil/404custom Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: UniteRechercheAvancee |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Set-Cookie: cookie_axis_stat=04daa7f7 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:47 GMT Content-Length: 79219 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="head ...[SNIP]... </script> <script type="text/javascript" src="http://s3.amazonaws ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/index.php |
GET /corporatif/index.php Accept: */* Referer: http://en.wikipedia.org Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive |
HTTP/1.1 200 OK Cache-Control: cache Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.13 Set-Cookie: POSTNUKESID=k6s9usn3 Set-Cookie: _lang=eng; expires=Thu, 16-Dec-2010 23:22:44 GMT X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:44 GMT Connection: close Content-Length: 21922 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"> <title>Couche-Tard | Home</title> <link rel="S ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /fr/accueil/404custom |
GET /fr/accueil/404custom Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: UniteRechercheAvancee |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Set-Cookie: cookie_axis_stat=04daa7f7 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:47 GMT Content-Length: 79219 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="head ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/includes |
GET /corporatif/includes Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: _lang=eng; POSTNUKESID=k6s9usn3 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Last-Modified: Wed, 26 May 2010 19:41:35 GMT Accept-Ranges: bytes ETag: "8041a73bfdca1:0" Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:44 GMT Content-Length: 51043 /* Copyright Mihai Bazon, 2002-2005 | www.bazon.net/mishoo * ------------------------- * * The DHTML Calendar, version 1.0 "It is happening again" * * De ...[SNIP]... <mihai_bazon@yahoo.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/includes |
GET /corporatif/includes Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: _lang=eng; POSTNUKESID=k6s9usn3 |
HTTP/1.1 200 OK Content-Type: application/x-javascript Last-Modified: Wed, 26 May 2010 19:42:03 GMT Accept-Ranges: bytes ETag: "d6d83d84bfdca1:0" Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:44 GMT Content-Length: 3727 // ** I18N // Calendar EN language // Author: Mihai Bazon, <mihai_bazon@yahoo.com> // Encoding: any // Distributed under the same terms as the calendar itself. // For translators: please use ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.couche-tard |
Path: | /corporatif/javascript |
GET /corporatif/javascript Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: _lang=eng; POSTNUKESID=k6s9usn3 |
HTTP/1.1 200 OK Content-Type: text/html Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.13 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:47 GMT Connection: close Content-Length: 224 function showimage() { if (!document.images) return document.images.avatar ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.couche-tard |
Path: | /corporatif/javascript |
GET /corporatif/javascript Accept: */* Referer: http://www.couche-tard Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.couche-tard.com Proxy-Connection: Keep-Alive Cookie: _lang=eng; POSTNUKESID=k6s9usn3 |
HTTP/1.1 200 OK Content-Type: text/html Vary: Accept-Encoding Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.13 X-Powered-By: ASP.NET Date: Tue, 16 Nov 2010 23:22:47 GMT Connection: close Content-Length: 224 function showimage() { if (!document.images) return document.images.avatar ...[SNIP]... |