1. Cross-site scripting (reflected)
1.1. http://www.insightbb.com/Auth/Authpartners.aspx [REST URL parameter 1]
1.2. http://www.insightbb.com/Auth/Authpartners.aspx [REST URL parameter 2]
Severity: | High |
Confidence: | Firm |
Host: | http://www.insightbb.com |
Path: | /Auth/Authpartners.aspx |
GET /Authb38eb'%3b63f855f76c5/Authpartners.aspx HTTP/1.1 Host: www.insightbb.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.5 Set-Cookie: ASP.NET_SessionId X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Sat, 06 Nov 2010 14:13:22 GMT Connection: close Content-Length: 46047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"> <HTML> <HEAD> <meta http-equiv="X-UA <title>Insight Broadband</title> <script type ...[SNIP]... if(event.srcElement.name == "txtZip"){ if (event.keyCode==13) { IsLocalZipValid('frmZip', } } }else{ if (e.target.name == "txtZip"){ if (e.keyCode==13) { IsLocalZipValid('frmZip', ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.insightbb.com |
Path: | /Auth/Authpartners.aspx |
GET /Auth/Authpartners.aspx51194'%3bf833bbb8ea9 HTTP/1.1 Host: www.insightbb.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not Found Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.5 Set-Cookie: ASP.NET_SessionId X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Sat, 06 Nov 2010 14:13:33 GMT Connection: close Content-Length: 45960 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"> <HTML> <HEAD> <meta http-equiv="X-UA <title>Insight Broadband</title> <script type ...[SNIP]... r") { if(event.srcElement.name == "txtZip"){ if (event.keyCode==13) { IsLocalZipValid('frmZip', } } }else{ if (e.target.name == "txtZip"){ if (e.keyCode==13) { IsLocalZipValid('frmZip', ...[SNIP]... |