<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-209 on ZAP</title>
    <link>/alerttags/cwe-209/</link>
    <description>Recent content in CWE-209 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-209/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>.NET stack trace / YSOD</title>
      <link>/docs/alerts/200010-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-3/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Full Path Disclosure</title>
      <link>/docs/alerts/110009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110009/</guid>
      <description>&lt;p&gt;The full path of files which might be sensitive has been exposed to the client.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Generic Padding Oracle</title>
      <link>/docs/alerts/90024/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90024/</guid>
      <description>&lt;p&gt;By manipulating the padding on an encrypted string, an attacker is able to generate an error message that indicates a likely &amp;lsquo;padding oracle&amp;rsquo; vulnerability. Such a vulnerability can affect any application or framework that uses encryption improperly, such as some versions of ASP.net, Java Server Faces, and Mono. An attacker may exploit this issue to decrypt data and recover encryption keys, potentially viewing and modifying confidential data. This rule should detect the MS10-070 padding oracle vulnerability in ASP.net if CustomErrors are enabled for that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Java Stack Trace</title>
      <link>/docs/alerts/100035/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100035/</guid>
      <description>&lt;p&gt;A Java stack trace was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - SQL Error</title>
      <link>/docs/alerts/100020/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100020/</guid>
      <description>&lt;p&gt;An SQL error was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Internal file path disclosure</title>
      <link>/docs/alerts/200010-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-6/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Java stack trace</title>
      <link>/docs/alerts/200010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-2/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Node.js / Express stack trace</title>
      <link>/docs/alerts/200010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-1/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>PHP fatal error / warning</title>
      <link>/docs/alerts/200010-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-5/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Python traceback</title>
      <link>/docs/alerts/200010-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-4/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
