1. Cross-site scripting (reflected)
1.3. http://www.quibids.com/auction.php [name of an arbitrarily supplied request parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.quibids.com |
Path: | /account/login_forgot.php |
GET /account/login_forgot.php Host: www.quibids.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: track_mbsession |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Date: Sat, 25 Dec 2010 19:11:52 GMT Keep-Alive: timeout=2, max=749 Connection: close Content-Length: 534 <html> <head> <title>QuiBids</title> <meta name="robots" content="noindex,nofollow <script>window.location= ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quibids.com |
Path: | /account/login_forgot.php |
GET /account/login_forgot.php Host: www.quibids.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: track_mbsession |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding,User Content-Type: text/html; charset=UTF-8 Date: Sat, 25 Dec 2010 19:11:49 GMT Keep-Alive: timeout=2, max=721 Connection: close Content-Length: 579 <html> <head> <title>QuiBids</title> <meta name="robots" content="noindex,nofollow <script>window.location= ...[SNIP]... <meta http-equiv="refresh" content="0; url=https://www.quibids ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.quibids.com |
Path: | /auction.php |
GET /auction.php?id=189533985 Host: www.quibids.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: track_mbsession |
HTTP/1.1 200 OK Server: Apache Vary: Accept-Encoding,User Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Content-Type: text/html; charset=UTF-8 Date: Sat, 25 Dec 2010 19:09:04 GMT Keep-Alive: timeout=2, max=743 Expires: Thu, 19 Nov 1981 08:52:00 GMT Pragma: no-cache Connection: close Content-Length: 30659 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... es', 'Easy to use and instantly fun, Kinect gets everyone off the couch moving, laughing and cheering.', 'http://s1.quibidscdn.com ...[SNIP]... |