1. Cross-site scripting (reflected)
2.1. https://taxes.hrblock.com/hrblock/login/ForgotAccountInfo.hrbx
2.2. https://taxes.hrblock.com/hrblock/login/LoginRegistration.hrbx
Severity: | High |
Confidence: | Certain |
Host: | https://taxes.hrblock.com |
Path: | /hrblock/login/Forgo |
GET /hrblock/login/Forgo Host: taxes.hrblock.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Expires: Fri, 01 Jan 1700 06:00:00 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Sat, 12 Feb 2011 18:35:17 GMT Connection: close Content-Length: 2162 <script language='JavaScript' id='LoadScript'>//p=new X.Page({Title:"Forgot Account Information",Require ...[SNIP]... faultTextBlockStyle"}, ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://taxes.hrblock.com |
Path: | /hrblock/login/Forgo |
GET /hrblock/login/Forgo Host: taxes.hrblock.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Expires: Fri, 01 Jan 1700 06:00:00 GMT Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Sat, 12 Feb 2011 18:35:05 GMT Connection: close Content-Length: 2031 <script language='JavaScript' id='LoadScript'>//p=new X.Page({Title:"Forgot Account Information",Require ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://taxes.hrblock.com |
Path: | /hrblock/login/Login |
GET /hrblock/login/Login Host: taxes.hrblock.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.5 X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET Date: Sat, 12 Feb 2011 18:36:17 GMT Connection: close Content-Length: 246 <script>var path = window.location.href; path = path.replace(/(&)?FV=.|(& ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://taxes.hrblock.com |
Path: | / |
Issued to: | taxes.hrblock.com |
Issued by: | VeriSign Class 3 Extended Validation SSL SGC CA |
Valid from: | Mon Aug 09 19:00:00 CDT 2010 |
Valid to: | Wed Aug 10 18:59:59 CDT 2011 |
Issued to: | VeriSign Class 3 Extended Validation SSL SGC CA |
Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Valid from: | Tue Nov 07 18:00:00 CST 2006 |
Valid to: | Mon Nov 07 17:59:59 CST 2016 |
Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 |
Issued by: | Class 3 Public Primary Certification Authority |
Valid from: | Tue Nov 07 18:00:00 CST 2006 |
Valid to: | Sun Nov 07 17:59:59 CST 2021 |
Issued to: | Class 3 Public Primary Certification Authority |
Issued by: | Class 3 Public Primary Certification Authority |
Valid from: | Sun Jan 28 18:00:00 CST 1996 |
Valid to: | Wed Aug 02 18:59:59 CDT 2028 |