2. Cross-site scripting (reflected)
3. Cookie without HttpOnly flag set
4. Cross-domain Referer leakage
Severity: | High |
Confidence: | Certain |
Host: | http://local.nissanusa |
Path: | /zip.aspx |
GET /zip.aspx?regionalZipCode Host: local.nissanusa.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache/2.2.15 (Fedora) X-Powered-By: PHP/5.3.2 Content-Type: text/html; charset=UTF-8 Expires: Fri, 28 Jan 2011 16:59:39 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 28 Jan 2011 16:59:39 GMT Content-Length: 5818 Connection: close Set-Cookie: PHPSESSID=2gc1h1bken <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... </div> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '27' AND a.version = 'en' AND ac.category_page='ZPA' AND' at line 5 |
GET /zip.aspx?regionalZipCode Host: local.nissanusa.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache/2.2.15 (Fedora) X-Powered-By: PHP/5.3.2 Content-Type: text/html; charset=UTF-8 Expires: Fri, 28 Jan 2011 16:59:39 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 28 Jan 2011 16:59:39 GMT Content-Length: 15976 Connection: close Set-Cookie: PHPSESSID=s9eoga6cao <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://local.nissanusa |
Path: | /zip.aspx |
GET /zip.aspx?regionalZipCode Host: local.nissanusa.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache/2.2.15 (Fedora) X-Powered-By: PHP/5.3.2 Content-Type: text/html; charset=UTF-8 Expires: Fri, 28 Jan 2011 16:59:39 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 28 Jan 2011 16:59:39 GMT Content-Length: 16017 Connection: close Set-Cookie: PHPSESSID=t7cgpte7k8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <input type="hidden" name="vehicle" value="versa-hatchback1e4e1"><script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://local.nissanusa |
Path: | /zip.aspx |
GET /zip.aspx HTTP/1.1 Host: local.nissanusa.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache/2.2.15 (Fedora) X-Powered-By: PHP/5.3.2 Content-Type: text/html; charset=UTF-8 Expires: Fri, 28 Jan 2011 16:59:34 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 28 Jan 2011 16:59:34 GMT Content-Length: 15938 Connection: close Set-Cookie: PHPSESSID=a3osnfcnbh <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://local.nissanusa |
Path: | /zip.aspx |
GET /zip.aspx?regionalZipCode Host: local.nissanusa.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache/2.2.15 (Fedora) X-Powered-By: PHP/5.3.2 Content-Type: text/html; charset=UTF-8 Expires: Fri, 28 Jan 2011 16:59:38 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 28 Jan 2011 16:59:38 GMT Content-Length: 15973 Connection: close Set-Cookie: PHPSESSID=p7dlskl4o4 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <noscript> <iframe src="http://fls ...[SNIP]... <li><a id="trade_in_value" target="_blank" href="http://web1 ...[SNIP]... |