3. Password field with autocomplete enabled
4. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | /mystuff/Login.do |
POST /4d5ed%0d%0a309b8a972b6/Login.do HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: https://travel.trave Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: travel.travelocity.com Connection: Keep-Alive Cache-Control: no-cache Cookie: TVLY_GEO=|||||; tyrg1st=61E8641635E69387; SID=T000V00000X30100 Content-Length: 39 es_alias=&es_passwd= |
HTTP/1.1 302 Moved Temporarily Date: Fri, 22 Oct 2010 06:51:02 GMT Server: Apache Location: http://travel.travelocity 309b8a972b6/Login.do;jsessionid Vary: Accept-Encoding Connection: close Content-Type: text/html; charset=ISO-8859-1 Content-Length: 0 |
Severity: | Low |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: travel.travelocity.com |
HTTP/1.1 200 OK Date: Fri, 22 Oct 2010 06:41:20 GMT Server: Apache Last-Modified: Fri, 26 Feb 2010 16:18:27 GMT ETag: "77cf2-5d6-3fd77ac0" Accept-Ranges: bytes Content-Length: 1494 Vary: Accept-Encoding Connection: close Content-Type: application/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*.travelocity.com" secure="false"/> ...[SNIP]... <allow-access-from domain="www.travelocity.com" secure="false"/> ...[SNIP]... <allow-access-from domain="i.travelocity.com" secure="false"/> ...[SNIP]... <allow-access-from domain="*.travelpn.com" secure="false"/> ...[SNIP]... <allow-access-from domain="i.travelpn.com.edgesuite ...[SNIP]... <allow-access-from domain="i.travelocity.com ...[SNIP]... <allow-access-from domain="travelocityf.download ...[SNIP]... <allow-access-from domain="ag.travelocity.com ...[SNIP]... <allow-access-from domain="hg.travelocity.com ...[SNIP]... <allow-access-from domain="design.int.travelocity ...[SNIP]... <allow-access-from domain="*.2mdn.net" secure="false"/> ...[SNIP]... <allow-access-from domain="*.vulnerable.ad.partner" secure="false"/> ...[SNIP]... <allow-access-from domain="ad.*.vulnerable.ad.partner" secure="false"/> ...[SNIP]... <allow-access-from domain="*.aolcdn.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.dotomi.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.sabre.com" secure="false" /> ...[SNIP]... <allow-access-from domain="ach.travel.yahoo.net" secure="false" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | /mystuff/Login.do |
POST /mystuff/Login.do HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: https://travel.trave Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: travel.travelocity.com Connection: Keep-Alive Cache-Control: no-cache Cookie: TVLY_GEO=|||||; tyrg1st=61E8641635E69387; SID=T000V00000X30100 Content-Length: 39 es_alias=&es_passwd= |
HTTP/1.1 200 OK Date: Fri, 22 Oct 2010 06:41:19 GMT Server: Apache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 29842 <!-- Copyright (C) 2005 Travelocity.com L.P. All rights reserved --> <script type="text/javascript" src="https://a248.e <timer:tim ...[SNIP]... <div id="logform" class="formcontent" style="display: block;"> <form name="LoginForm" action="Login.do" method="post"> <div class="e_box" id="e_box"> ...[SNIP]... </span> <input type="password" class="formpsw" name="es_passwd" /> </div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | /mystuff/Login.do |
POST /mystuff/Login.do HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: https://travel.trave Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: travel.travelocity.com Connection: Keep-Alive Cache-Control: no-cache Cookie: TVLY_GEO=|||||; tyrg1st=61E8641635E69387; SID=T000V00000X30100 Content-Length: 39 es_alias=&es_passwd= |
HTTP/1.1 200 OK Date: Fri, 22 Oct 2010 06:41:19 GMT Server: Apache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 29842 <!-- Copyright (C) 2005 Travelocity.com L.P. All rights reserved --> <script type="text/javascript" src="https://a248.e <timer:tim ...[SNIP]... <body id="login" > <script language="javascript" type="text/javascript" src="https://a248.e ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | / |
TRACE / HTTP/1.0 Host: travel.travelocity.com Cookie: 5d56f156a767850d |
HTTP/1.1 200 OK Date: Fri, 22 Oct 2010 06:41:20 GMT Server: Apache Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: travel.travelocity.com Cookie: 5d56f156a767850d X-Forwarded-For: 204.51.113.169 |
Severity: | Information |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | /mystuff/Login.do |
GET /robots.txt HTTP/1.0 Host: travel.travelocity.com |
HTTP/1.1 200 OK Date: Fri, 22 Oct 2010 06:41:22 GMT Server: Apache Last-Modified: Fri, 30 Oct 2009 13:04:04 GMT ETag: "16adb7-cb-a98e9900" Accept-Ranges: bytes Content-Length: 203 Vary: Accept-Encoding Connection: close Content-Type: text/plain; charset=ISO-8859-1 User-agent: * Disallow: Sitemap: http://travel.travelocity Sitemap: http://hotels.travelocity Sitemap: http://hotels.travelocity ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | /mystuff/Login.do |
POST /mystuff/Login.do HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: https://travel.trave Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: travel.travelocity.com Connection: Keep-Alive Cache-Control: no-cache Cookie: TVLY_GEO=|||||; tyrg1st=61E8641635E69387; SID=T000V00000X30100 Content-Length: 39 es_alias=&es_passwd= |
HTTP/1.1 200 OK Date: Fri, 22 Oct 2010 06:41:19 GMT Server: Apache Vary: Accept-Encoding Connection: close Content-Type: text/html;charset=UTF-8 Content-Length: 29842 <!-- Copyright (C) 2005 Travelocity.com L.P. All rights reserved --> <script type="text/javascript" src="https://a248.e <timer:tim ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://travel.trave |
Path: | / |
Issued to: | travel.travelocity.com |
Issued by: | VeriSign Class 3 Extended Validation SSL SGC CA |
Valid from: | Thu Jan 28 19:00:00 EST 2010 |
Valid to: | Sun Jan 29 18:59:59 EST 2012 |
Issued to: | VeriSign Class 3 Extended Validation SSL SGC CA |
Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Valid from: | Tue Nov 07 19:00:00 EST 2006 |
Valid to: | Mon Nov 07 18:59:59 EST 2016 |
Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Issued by: | Class 3 Public Primary Certification Authority |
Valid from: | Tue Nov 07 19:00:00 EST 2006 |
Valid to: | Sun Nov 07 18:59:59 EST 2021 |
Issued to: | Class 3 Public Primary Certification Authority |
Issued by: | Class 3 Public Primary Certification Authority |
Valid from: | Sun Jan 28 19:00:00 EST 1996 |
Valid to: | Wed Aug 02 19:59:59 EDT 2028 |