1. Cleartext submission of password
2. Password field with autocomplete enabled
3. Cross-domain script include
4. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://www.rockettheme |
Path: | / |
GET / HTTP/1.1 Host: www.rockettheme.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 18:26:16 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.12 X-Powered-By: PHP/5.2.12 Set-Cookie: cd6974ce18b02e32626c P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Sat, 20 Nov 2010 18:26:16 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 41417 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <div id="rokclub-login" class="login"> <form action="/index.php" method="post" id="form-login" > <fieldset class="input"> ...[SNIP]... <br /> <input id="modlgn_passwd" type="password" name="passwd" class="inputbox" size="18" alt="password" /> </p> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.rockettheme |
Path: | / |
GET / HTTP/1.1 Host: www.rockettheme.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 18:26:16 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.12 X-Powered-By: PHP/5.2.12 Set-Cookie: cd6974ce18b02e32626c P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Sat, 20 Nov 2010 18:26:16 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 41417 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <div id="rokclub-login" class="login"> <form action="/index.php" method="post" id="form-login" > <fieldset class="input"> ...[SNIP]... <br /> <input id="modlgn_passwd" type="password" name="passwd" class="inputbox" size="18" alt="password" /> </p> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.rockettheme |
Path: | / |
GET / HTTP/1.1 Host: www.rockettheme.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 18:26:16 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.12 X-Powered-By: PHP/5.2.12 Set-Cookie: cd6974ce18b02e32626c P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Sat, 20 Nov 2010 18:26:16 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 41417 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... </div> <script src='http://static ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.rockettheme |
Path: | / |
GET / HTTP/1.1 Host: www.rockettheme.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Sat, 20 Nov 2010 18:26:16 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.12 X-Powered-By: PHP/5.2.12 Set-Cookie: cd6974ce18b02e32626c P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Last-Modified: Sat, 20 Nov 2010 18:26:16 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 41417 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |