2. Cross-domain script include
3. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www.redhat.com |
Path: | /apps/redirect.apm/http |
GET /apps/redirect.apm/http381ad%0d%0a16a458bf924/press.redhat.com HTTP/1.1 Host: www.redhat.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; CloudScan Vuln Crawler http://cloudscan.me) Connection: close |
HTTP/1.1 302 Moved Temporarily Server: Apache Location: http381ad 16a458bf924: //press.redhat.com/ Content-Length: 0 Content-Type: text/html; charset=iso-8859-1 Vary: Accept-Encoding Expires: Fri, 12 Nov 2010 13:33:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 12 Nov 2010 13:33:53 GMT Connection: close |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.redhat.com |
Path: | /summit/callforpapers/ |
GET /summit/callforpapers/ HTTP/1.1 Host: www.redhat.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; CloudScan Vuln Crawler http://cloudscan.me) Connection: close |
HTTP/1.1 200 OK Server: Apache Content-Type: text/html; charset=UTF-8 Expires: Fri, 12 Nov 2010 13:33:34 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 12 Nov 2010 13:33:34 GMT Content-Length: 8272 Connection: close X-N: S <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <ti ...[SNIP]... <link rel="stylesheet" type="text/css" media="screen, projection" href="/summit/css/nivo <script type="text/javascript" src="http://ajax ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.redhat.com |
Path: | /robots.txt |
GET /robots.txt HTTP/1.1 Host: www.redhat.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; CloudScan Vuln Crawler http://cloudscan.me) Connection: close |
HTTP/1.1 200 OK Server: Apache Last-Modified: Fri, 11 Jun 2010 14:57:27 GMT ETag: "65badf-16f-488c25b8023c0 Accept-Ranges: bytes Content-Length: 367 Content-Type: text/plain; charset=UTF-8 Date: Fri, 12 Nov 2010 12:59:10 GMT Connection: close User-agent: * Disallow: /apps/download/results Disallow: /apps/search/results.html Disallow: /apps/user/ Disallow: /apps/user/* Disallow: /WebX/* Disallow: /webx/* Disallow: /WebX/* Disallow: /te ...[SNIP]... |