1. Cross-site scripting (reflected)
2. Cookie without HttpOnly flag set
3. Cross-domain script include
Severity: | High |
Confidence: | Certain |
Host: | http://www.virtacore.com |
Path: | / |
GET /?c5a33</script><script Host: www.virtacore.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 18 Feb 2011 14:52:41 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=11144942;expires=Sun Set-Cookie: CFTOKEN=96782673;expires Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <!-- _uacct='UA-19578445-1' ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.virtacore.com |
Path: | / |
GET / HTTP/1.1 Host: www.virtacore.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 18 Feb 2011 14:52:39 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=11144923;expires=Sun Set-Cookie: CFTOKEN=14899720;expires Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.virtacore.com |
Path: | / |
GET / HTTP/1.1 Host: www.virtacore.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Connection: close Date: Fri, 18 Feb 2011 14:52:39 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: CFID=11144923;expires=Sun Set-Cookie: CFTOKEN=14899720;expires Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <![endif]--> <script src="http://www.google ...[SNIP]... </script><script type='text/javascript' src='https://ajax ...[SNIP]... |