1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3. Cross-domain Referer leakage
5. HTML does not specify charset
6. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.radiocentraal |
Path: | /Realescape/programmatie |
GET /Realescape/programmatie Host: www.radiocentraal.be Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 10 Dec 2010 02:29:39 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.2.14-0.dotdeb.0pw1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=ff47cace8f Set-Cookie: radio_centraal_restyle Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 21972 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="nl"> <!-- Copyright: Op deze website en de broncode berust copyright. Implementatie van delen va ...[SNIP]... ax_target_id); target_id = sajax_target_id; if (typeof(sajax_request sajax_request_type = "GET"; uri = "/Realescape/programmatie if (sajax_request_type == "GET") { if (uri.indexOf("?") == -1) uri += "?rs=" + escape(func_name); else uri += "&rs=" + escape(func_name); uri += "&rst=" + escape(saja ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.radiocentraal |
Path: | /Realescape/programmatie |
GET /Realescape/programmatie Host: www.radiocentraal.be Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Fri, 10 Dec 2010 02:29:26 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.2.14-0.dotdeb.0pw1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=e8af6a78f3 Set-Cookie: radio_centraal_restyle Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 17253 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="nl"> <!-- Copyright: Op deze website en de broncode berust copyright. Implementatie van delen va ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.radiocentraal |
Path: | /Realescape/programmatie |
GET /Realescape/programmatie Host: www.radiocentraal.be Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=25cd33a28c |
HTTP/1.1 200 OK Date: Fri, 10 Dec 2010 03:24:40 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.2.14-0.dotdeb.0pw1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 22020 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="nl"> <!-- Copyright: Op deze website en de broncode berust copyright. Implementatie van delen va ...[SNIP]... <p class="center"><a href="http://streaming ...[SNIP]... <div><a href="http://webgang ...[SNIP]... <div><a href="http://redactie ...[SNIP]... <li><a href='http://redactie ...[SNIP]... <li><a href='http://redactie ...[SNIP]... <li><a href='http://redactie ...[SNIP]... <li><a href='http://redactie ...[SNIP]... <li><a href='http://redactie ...[SNIP]... <div id="menu_extra"> <a href="http://redactie ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.radiocentraal |
Path: | /Realescape/functions |
GET /Realescape/functions Host: www.radiocentraal.be Proxy-Connection: keep-alive Referer: http://www.radiocentraal Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=25cd33a28c |
HTTP/1.1 200 OK Date: Fri, 10 Dec 2010 03:24:21 GMT Server: Apache/2.2.14 (Ubuntu) Last-Modified: Sun, 19 Sep 2010 17:28:42 GMT ETag: "3c1d65-1572-490a020 Accept-Ranges: bytes Vary: Accept-Encoding Content-Type: application/javascript Content-Length: 5490 /* Licensed public domain * Script overgenomen van ijbema@xs4all.nl Waarvoor dank */ /* * addLoadEvent based upon this blog article: * * http://simon.incutio.com */ function addLoadEvent(func) { var oldonload = window.onload; if ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.radiocentraal |
Path: | /Realescape/actors/get |
GET /Realescape/actors/get Host: www.radiocentraal.be Proxy-Connection: keep-alive Referer: http://www.radiocentraal Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=25cd33a28c |
HTTP/1.1 200 OK Date: Fri, 10 Dec 2010 03:24:29 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.2.14-0.dotdeb.0pw1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 162 boventekst_0=Nachtmachine |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.radiocentraal |
Path: | /Realescape/actors/get |
GET /Realescape/actors/get Host: www.radiocentraal.be Proxy-Connection: keep-alive Referer: http://www.radiocentraal Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=25cd33a28c |
HTTP/1.1 200 OK Date: Fri, 10 Dec 2010 03:24:29 GMT Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.2.14-0.dotdeb.0pw1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 162 boventekst_0=Nachtmachine |