1. Cross-site scripting (reflected)
3. Cookie scoped to parent domain
4. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://www.splunk.com |
Path: | / |
GET /?fee9d--><script>alert(1)< Host: www.splunk.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:48 GMT Server: Apache/2.2.8 (EL) Vary: Host,Accept-Encoding,User Set-Cookie: Apache=173.193.214.243 X-Powered-By: PHP/5.2.6 Set-Cookie: XARAYASID=uahgvq28ho Expires: 0 Cache-Control: public, must-revalidate Pragma: ETag: b0e1dfbf44786a21b073 Last-Modified: Tue, 08 Feb 2011 18:41:50 GMT Connection: close Content-Type: text/html; charset=utf-8 Content-Length: 55886 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <!-- SID:24 GEN:2011-02-08T10:41:50 ...[SNIP]... |
Severity: | Low |
Confidence: | Tentative |
Host: | http://www.splunk.com |
Path: | / |
GET / HTTP/1.1 Host: www.splunk.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:04 GMT Server: Apache/2.2.8 (EL) Vary: Host,Accept-Encoding,User Set-Cookie: Apache=173.193.214.243 X-Powered-By: PHP/5.2.6 Set-Cookie: XARAYASID=8v5n9h6lp4 Expires: 0 Cache-Control: public, must-revalidate Pragma: ETag: 3d14396a178718eef57f Last-Modified: Tue, 08 Feb 2011 18:38:28 GMT Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 55788 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... :5px; } #quoteItemNav { float:left; margin-right:8px; width:37px; } #quoteItemNav a { display:block; float:right; height:20px; width:15px; margin-top:5px; background-image:url(<?= $SrvURL ?>themes/splunk_com/css background-repeat:no } #quoteItemNav a#quoteItemFwd { background-position:-13px 7px; } #quoteItemNav a#quoteItemrBack { background-positio ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.splunk.com |
Path: | / |
GET / HTTP/1.1 Host: www.splunk.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:04 GMT Server: Apache/2.2.8 (EL) Vary: Host,Accept-Encoding,User Set-Cookie: Apache=173.193.214.243 X-Powered-By: PHP/5.2.6 Set-Cookie: XARAYASID=8v5n9h6lp4 Expires: 0 Cache-Control: public, must-revalidate Pragma: ETag: 3d14396a178718eef57f Last-Modified: Tue, 08 Feb 2011 18:38:28 GMT Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 55788 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.splunk.com |
Path: | / |
GET / HTTP/1.1 Host: www.splunk.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:04 GMT Server: Apache/2.2.8 (EL) Vary: Host,Accept-Encoding,User Set-Cookie: Apache=173.193.214.243 X-Powered-By: PHP/5.2.6 Set-Cookie: XARAYASID=8v5n9h6lp4 Expires: 0 Cache-Control: public, must-revalidate Pragma: ETag: 3d14396a178718eef57f Last-Modified: Tue, 08 Feb 2011 18:38:28 GMT Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 55788 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.splunk.com |
Path: | / |
TRACE / HTTP/1.0 Host: www.splunk.com Cookie: 36abcb3b73dc9e20 |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:04 GMT Server: Apache/2.2.8 (EL) Vary: Host Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: www.splunk.com Cookie: 36abcb3b73dc9e20 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.splunk.com |
Path: | / |
GET /robots.txt HTTP/1.0 Host: www.splunk.com |
HTTP/1.1 200 OK Date: Tue, 08 Feb 2011 18:41:06 GMT Server: Apache/2.2.8 (EL) Vary: Host,Accept-Encoding,User Set-Cookie: Apache=173.193.214.243 Last-Modified: Wed, 17 Nov 2010 21:45:29 GMT ETag: "100187-528-4954697827040 Accept-Ranges: bytes Content-Length: 1320 Connection: close Content-Type: text/plain; charset=UTF-8 User-agent: gsa-crawler-splunk # Even tho identical to below, we will continue to keep this section in case we want to add to it Disallow: /base/index.php # Do not allow index.php with an ...[SNIP]... |