1. Cross-site scripting (reflected)
1.1. https://idp.securepaynet.net/Error.aspx [spkey parameter]
1.2. https://idp.securepaynet.net/Error.aspx [spkey parameter]
1.3. https://idp.securepaynet.net/Error.aspx [spkey parameter]
Severity: | High |
Confidence: | Certain |
Host: | https://idp.securepaynet |
Path: | /Error.aspx |
GET /Error.aspx?ci=9106&prog Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Encoding: gzip, deflate Cookie: currency459469=potab Host: idp.securepaynet.net Connection: Keep-Alive Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) |
HTTP/1.1 200 OK Date: Thu, 28 Oct 2010 19:20:01 GMT Server: Microsoft-IIS/6.0 P3P: CP="IDC DSP COR LAW CUR ADM DEV TAI PSA PSD IVA IVD HIS OUR SAM PUB LEG UNI COM NAV STA" X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Set-Cookie: traffic=; domain=securepaynet.net; path=/ Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 87597 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>My Account - An Error Occurred</title> <l ...[SNIP]... repaynet.net/"; var pcj_url_img="https://img5 var pcj_url_mya="https://mya var pcj_login_root_url="https var pcj_ssoTargetKey = "target"; var pcj_isCart = false; var pcj_cname = "ShopperId459465"; var pcj_cdomain = ".securepaynet.net"; var pcj_callov = false; var pcj_call = true; var pcj_isMgr = false; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://idp.securepaynet |
Path: | /Error.aspx |
GET /Error.aspx?ci=9106&prog Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Encoding: gzip, deflate Cookie: currency459469=potab Host: idp.securepaynet.net Connection: Keep-Alive Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) |
HTTP/1.1 200 OK Date: Thu, 28 Oct 2010 19:20:02 GMT Server: Microsoft-IIS/6.0 P3P: CP="IDC DSP COR LAW CUR ADM DEV TAI PSA PSD IVA IVD HIS OUR SAM PUB LEG UNI COM NAV STA" X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Set-Cookie: traffic=; domain=securepaynet.net; path=/ Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 88181 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>My Account - An Error Occurred</title> <l ...[SNIP]... mya="https://mya var pcj_login_root_url="https var pcj_ssoTargetKey = "target"; var pcj_isCart = false; var pcj_cname = "ShopperId459465"; var pcj_cdomain = ".securepaynet.net"; var pcj_callov = false; var pcj_call = true; var pcj_isMgr = false; ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://idp.securepaynet |
Path: | /Error.aspx |
GET /Error.aspx?ci=9106&prog Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Encoding: gzip, deflate Cookie: currency459469=potab Host: idp.securepaynet.net Connection: Keep-Alive Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) |
HTTP/1.1 200 OK Date: Thu, 28 Oct 2010 19:19:50 GMT Server: Microsoft-IIS/6.0 P3P: CP="IDC DSP COR LAW CUR ADM DEV TAI PSA PSD IVA IVD HIS OUR SAM PUB LEG UNI COM NAV STA" X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Set-Cookie: traffic=; domain=securepaynet.net; path=/ Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 88331 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title>My Account - An Error Occurred</title> <l ...[SNIP]... n: 0;" name="pchFL" id="pchFL" method="POST" action="https://idp ...[SNIP]... |