1. Cross-site scripting (reflected)
2. SSL cookie without secure flag set
Severity: | High |
Confidence: | Certain |
Host: | https://4qinvite.4q |
Path: | /1.aspx |
GET /1.aspx?sdfc=299f610e Host: 4qinvite.4q.iperceptions Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sun, 21 Nov 2010 17:17:11 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-Srv-By: 4Q-INVITE2 X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 1089 var sID= '24038'; var sC= 'IPE24038'; var brow= 'IE'; var vers= '7.0'; var lID= '1'; var loc= '4Q-WEB2'; var ps= 'sdfc=299f610e-24038 ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://4qinvite.4q |
Path: | /1.aspx |
POST /1.aspx?sdfc=299f610e Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Accept-Language: en-US Host: 4qinvite.4q.iperceptions Connection: Keep-Alive Cache-Control: no-cache Content-Length: 48 button=show+response |
HTTP/1.1 200 OK Date: Sun, 21 Nov 2010 18:58:25 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-Srv-By: 4Q-INVITE2 X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Cache-Control: private Content-Length: 0 |