1.1. http://barronsonline.fundinfo.wilink.com/v5/index.asp [REST URL parameter 1]
1.2. http://barronsonline.fundinfo.wilink.com/v5/index.asp [REST URL parameter 2]
Severity: | High |
Confidence: | Certain |
Host: | http://barronsonline |
Path: | /v5/index.asp |
GET /v5'/index.asp HTTP/1.1 Host: barronsonline.fundinfo Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 500 Internal Server Error Connection: close Date: Sat, 06 Nov 2010 16:27:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 349 Content-Type: text/html Set-Cookie: ASPSESSIONIDASQRRRDD Cache-control: private <font face="Arial" size=2> <p>Microsoft OLE DB Provider for ODBC Drivers</font> <font face="Arial" size=2>error '80040e14'</font> <p> <font face="Arial" size=2>[Microsoft][ODBC SQL Server Driver][SQL Server]Incorrect syntax near the keyword 'index'.</font> ...[SNIP]... |
GET /v5''/index.asp HTTP/1.1 Host: barronsonline.fundinfo Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sat, 06 Nov 2010 16:27:35 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 0 Content-Type: text/html Set-Cookie: ASPSESSIONIDASQRRRDD Cache-control: private |
Severity: | High |
Confidence: | Certain |
Host: | http://barronsonline |
Path: | /v5/index.asp |
GET /v5/index.asp' HTTP/1.1 Host: barronsonline.fundinfo Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 500 Internal Server Error Connection: close Date: Sat, 06 Nov 2010 16:27:37 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 395 Content-Type: text/html Set-Cookie: ASPSESSIONIDASQRRRDD Cache-control: private <font face="Arial" size=2> <p>Microsoft OLE DB Provider for ODBC Drivers</font> <font face="Arial" size=2>error '80040e14'</font> <p> <font face="Arial" size=2>[Microsoft][ODBC SQL Server Driver][SQL Server]Unclosed quotation mark before the character string 'fundinfo.wilink.com/v5 ...[SNIP]... |
GET /v5/index.asp'' HTTP/1.1 Host: barronsonline.fundinfo Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Sat, 06 Nov 2010 16:27:37 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 0 Content-Type: text/html Set-Cookie: ASPSESSIONIDASQRRRDD Cache-control: private |