1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3. Cross-domain script include
| Severity: | High |
| Confidence: | Certain |
| Host: | http://www.virtacore.com |
| Path: | / |
| GET /?c5a33</script><script Host: www.virtacore.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Connection: close Date: Fri, 18 Feb 2011 14:52:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=11144942;expires=Sun Set-Cookie: CFTOKEN=96782673;expires Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <!-- _uacct='UA-19578445-1' ...[SNIP]... |
| Severity: | Low |
| Confidence: | Firm |
| Host: | http://www.virtacore.com |
| Path: | / |
| GET / HTTP/1.1 Host: www.virtacore.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Connection: close Date: Fri, 18 Feb 2011 14:52:39 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=11144923;expires=Sun Set-Cookie: CFTOKEN=14899720;expires Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... |
| Severity: | Information |
| Confidence: | Certain |
| Host: | http://www.virtacore.com |
| Path: | / |
| GET / HTTP/1.1 Host: www.virtacore.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
| HTTP/1.1 200 OK Connection: close Date: Fri, 18 Feb 2011 14:52:39 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=11144923;expires=Sun Set-Cookie: CFTOKEN=14899720;expires Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <![endif]--> <script src="http://www.google ...[SNIP]... </script><script type='text/javascript' src='https://ajax ...[SNIP]... |