1. Cross-site scripting (reflected)
2. Cross-domain script include
2.2. http://projects.webappsec.org/w/page/13246986/a
3. Cookie without HttpOnly flag set
3.2. http://projects.webappsec.org/w/page/13246986/a
4.1. http://projects.webappsec.org/api_v2/
4.3. http://projects.webappsec.org/w/page/13246986/a
Severity: | High |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /w/page/13246986/Web |
GET /w/page/13246986/Web Host: projects.webappsec.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:04:20 GMT Content-Type: text/html; charset=utf-8 Connection: close Expires: Tue, 04 Jan 2011 19:04:19 GMT Cache-Control: no-cache Set-Cookie: pbj=e23b39fbc0e0db59 Content-Length: 102154 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="cont ...[SNIP]... <b>Web-Application ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /w/page/13246986/Web |
GET /w/page/13246986/Web Host: projects.webappsec.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:04:03 GMT Content-Type: text/html; charset=utf-8 Connection: close Expires: Tue, 04 Jan 2011 19:04:03 GMT Cache-Control: no-cache Set-Cookie: pbj=9e4eeab0d19ff276 Content-Length: 102407 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="cont ...[SNIP]... </script> <script type="text/javascript" src="http://vs1.pbworks <script type="text/javascript" src="http://vs1.pbworks <script type="text/javascript" src="http://vs1.pbworks ...[SNIP]... <!-- Start Quantcast tag --> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /w/page/13246986/a |
GET /w/page/13246986/a HTTP/1.1 Host: projects.webappsec.org Proxy-Connection: keep-alive Referer: http://projects.webappsec Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=133238479 |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:13:04 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Expires: Tue, 04 Jan 2011 19:13:04 GMT Cache-Control: no-cache Content-Length: 102044 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="cont ...[SNIP]... </script> <script type="text/javascript" src="http://vs1.pbworks <script type="text/javascript" src="http://vs1.pbworks <script type="text/javascript" src="http://vs1.pbworks ...[SNIP]... <!-- Start Quantcast tag --> <script type="text/javascript" src="http://edge ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /w/page/13246986/Web |
GET /w/page/13246986/Web Host: projects.webappsec.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:04:03 GMT Content-Type: text/html; charset=utf-8 Connection: close Expires: Tue, 04 Jan 2011 19:04:03 GMT Cache-Control: no-cache Set-Cookie: pbj=9e4eeab0d19ff276 Content-Length: 102407 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="cont ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /w/page/13246986/a |
GET /w/page/13246986/a HTTP/1.1 Host: projects.webappsec.org Proxy-Connection: keep-alive Referer: http://projects.webappsec Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=133238479 |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:15:09 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Set-Cookie: pb_perfmon=deleted; expires=Tue, 05-Jan-2010 19:15:08 GMT; path=/ Expires: Tue, 04 Jan 2011 19:15:09 GMT Cache-Control: no-cache Content-Length: 102044 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="cont ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /api_v2/ |
GET /api_v2/?count=7&pagetime Host: projects.webappsec.org Proxy-Connection: keep-alive Referer: http://projects.webappsec X-Prototype-Version: 1.6.1 X-Requested-With: XMLHttpRequest Accept: text/javascript, text/html, application/xml, text/xml, */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: pbj=37794d22f217b81f |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:12:50 GMT Content-Type: application/json Connection: keep-alive Expires: Thu, 01 Jan 2037 00:00:00 GMT Cache-Control: private, max-age=1209600 Vary: Accept-Encoding Content-Length: 4032 /*-secure- {"_auth_role":"read"," ...[SNIP]... otection-Working","type": ...[SNIP]... otection-Working","type": ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /w/page/13246986/Web |
GET /w/page/13246986/Web Host: projects.webappsec.org Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:04:03 GMT Content-Type: text/html; charset=utf-8 Connection: close Expires: Tue, 04 Jan 2011 19:04:03 GMT Cache-Control: no-cache Set-Cookie: pbj=9e4eeab0d19ff276 Content-Length: 102407 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="cont ...[SNIP]... times":{"pagetime" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://projects.webappsec |
Path: | /w/page/13246986/a |
GET /w/page/13246986/a HTTP/1.1 Host: projects.webappsec.org Proxy-Connection: keep-alive Referer: http://projects.webappsec Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=133238479 |
HTTP/1.1 200 OK Server: nginx/0.6.32 Date: Wed, 05 Jan 2011 19:13:04 GMT Content-Type: text/html; charset=utf-8 Connection: keep-alive Expires: Tue, 04 Jan 2011 19:13:04 GMT Cache-Control: no-cache Content-Length: 102044 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="cont ...[SNIP]... times":{"pagetime" ...[SNIP]... |