<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-327 on ZAP</title>
    <link>/alerttags/cwe-327/</link>
    <description>Recent content in CWE-327 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-327/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Information Disclosure - Hash</title>
      <link>/docs/alerts/100010/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100010/</guid>
      <description>&lt;p&gt;A hash was discovered in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Telerik UI for ASP.NET AJAX Cryptographic Weakness (CVE-2017-9248)</title>
      <link>/docs/alerts/100021/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100021/</guid>
      <description>&lt;p&gt;A request has been made that appears to conform to poor cryptography used by Telerik UI for ASP.NET AJAX prior to v2017.2.621.&#xA;An attacker could manipulate the value of the dp parameter to possibly learn the machine key and upload arbitrary files, which could then lead to the compromise of ASP.NET ViewStates and arbitrary code execution respectively.&#xA;CVE-2017-9248 has a CVSSv3 score of 9.8.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
