2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://www.myproduct |
Path: | /mpa/autobytel/setCookie |
GET /mpa/7d2d3%0d%0a4fb5754f9c5/setCookie.do HTTP/1.1 Host: www.myproductadvisor.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Moved Temporarily Date: Tue, 25 Jan 2011 00:08:56 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: UIVERSION_COOKIE=1; Path=/mpa/ Location: http://www.myproduct 4fb5754f9c5/setCookie.do Content-Length: 0 P3P: policyref="/content/w3c Connection: close Content-Type: text/plain; charset=UTF-8 |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.myproduct |
Path: | /mpa/autobytel/setCookie |
GET /mpa/autobytel/setCookie Host: www.myproductadvisor.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Moved Temporarily Date: Tue, 25 Jan 2011 00:08:23 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: UIVERSION_COOKIE=1; Path=/mpa/ Set-Cookie: JSESSIONID=a7ff3102c Location: http://www.myproduct Content-Length: 0 P3P: policyref="/content/w3c Connection: close Content-Type: text/html; charset=UTF-8 Set-Cookie: Coyote-2-c0a8010b |