1. Cross-site scripting (reflected)
1.1. http://www.stericycle.com/inforequest.html [type parameter]
1.2. http://www.stericycle.com/inforequest.html [type parameter]
2. Cookie without HttpOnly flag set
4. Cross-domain Referer leakage
5.1. http://www.stericycle.com/contact-us.html
5.2. http://www.stericycle.com/js/dragdrop.js
Severity: | High |
Confidence: | Certain |
Host: | http://www.stericycle.com |
Path: | /inforequest.html |
GET /inforequest.html?type Host: www.stericycle.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: stericycle_session |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 18:21:09 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding P3P: CP="NON" Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13222 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Contact Stericycle</t ...[SNIP]... <!-- function submitContactForm() { var contactType = 'customere1ddb'-alert(1)- var errors = []; var error_srting = ''; var form_el = $('contact_form'); var req_text_vals = [["first_name","First Name"],["last_name","Last Name"],["state","State"], ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.stericycle.com |
Path: | /inforequest.html |
GET /inforequest.html?type Host: www.stericycle.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: stericycle_session |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 18:21:08 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding P3P: CP="NON" Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13250 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Contact Stericycle</t ...[SNIP]... <input type=hidden name="customerType" value="customer8e69c"><script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.stericycle.com |
Path: | / |
GET / HTTP/1.1 Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.stericycle.com |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 18:20:20 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Set-Cookie: stericycle_session Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding P3P: CP="NON" Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 34382 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Stericycle - Med ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stericycle.com |
Path: | /inforequest.html |
GET /inforequest.html?type Host: www.stericycle.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: stericycle_session |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 18:21:00 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding P3P: CP="NON" Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13534 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Contact Stericycle</t ...[SNIP]... <div class="form" id="contact_form <form action="https://www <fieldset id="personal_info"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stericycle.com |
Path: | /inforequest.html |
GET /inforequest.html?type Host: www.stericycle.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: stericycle_session |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 18:21:00 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding P3P: CP="NON" Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13307 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Contact Stericycle</t ...[SNIP]... <noscript> <iframe src="http://view.atdmt ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stericycle.com |
Path: | /contact-us.html |
GET /contact-us.html HTTP/1.1 Host: www.stericycle.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: stericycle_session |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 18:21:02 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: PHP/5.1.6 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Vary: Accept-Encoding P3P: CP="NON" Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 8920 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <title>Contact Us - Stericyc ...[SNIP]... <a href="mailto:customercare@stericycle ...[SNIP]... <a href="mailto:asktheexperts@stericycle ...[SNIP]... <a href="mailto:global@stericycle.com">global@stericycle.com</a> ...[SNIP]... <a href="mailto:investor@stericycle.com">investor@stericycle.com</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.stericycle.com |
Path: | /js/dragdrop.js |
GET /js/dragdrop.js HTTP/1.1 Accept: */* Referer: http://www.stericycle.com Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET4.0C; .NET4.0E; .NET CLR 3.5.30729; .NET CLR 3.0.30729) Accept-Encoding: gzip, deflate Host: www.stericycle.com Proxy-Connection: Keep-Alive Cookie: stericycle_session |
HTTP/1.1 200 OK Date: Tue, 16 Nov 2010 18:21:08 GMT Server: Apache/2.2.3 (Red Hat) Accept-Ranges: bytes Vary: Accept-Encoding P3P: CP="NON" Cache-Control: max-age=290304000, public Connection: close Content-Type: application/x-javascript Content-Length: 31408 // script.aculo.us dragdrop.js v1.7.1_beta3, Fri May 25 17:19:41 +0200 2007 // Copyright (c) 2005-2007 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us) // (c) 2005-2007 Sammi Williams (http://www.oriontransfer // // script.aculo.us is freely distributable under the terms of an MIT-style license. // For details, see the script.aculo.us web site: http://script.aculo.us/ if(typeof Effect == 'undefined') t ...[SNIP]... |