<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-497 on ZAP</title>
    <link>/alerttags/cwe-497/</link>
    <description>Recent content in CWE-497 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-497/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Hash Disclosure - BCrypt</title>
      <link>/docs/alerts/10097-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-7/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - BCrypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - Kerberos AFS DES</title>
      <link>/docs/alerts/10097-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-2/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - Kerberos AFS DES&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - LanMan</title>
      <link>/docs/alerts/10097-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-15/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - LanMan&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - LanMan / DES</title>
      <link>/docs/alerts/10097-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-1/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - LanMan / DES&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - MD4 / MD5</title>
      <link>/docs/alerts/10097-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-16/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - MD4 / MD5&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - MD5 Crypt</title>
      <link>/docs/alerts/10097-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-4/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - MD5 Crypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - NTLM</title>
      <link>/docs/alerts/10097-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-8/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - NTLM&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - OpenBSD Blowfish</title>
      <link>/docs/alerts/10097-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-3/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - OpenBSD Blowfish&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - Salted SHA-1</title>
      <link>/docs/alerts/10097-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-9/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - Salted SHA-1&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-1</title>
      <link>/docs/alerts/10097-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-14/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-1&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-224</title>
      <link>/docs/alerts/10097-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-13/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-224&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-256</title>
      <link>/docs/alerts/10097-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-12/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-256&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-256 Crypt</title>
      <link>/docs/alerts/10097-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-5/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-256 Crypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-384</title>
      <link>/docs/alerts/10097-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-11/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-384&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-512</title>
      <link>/docs/alerts/10097-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-10/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-512&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-512 Crypt</title>
      <link>/docs/alerts/10097-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-6/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-512 Crypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>In Page Banner Information Leak</title>
      <link>/docs/alerts/10009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10009/</guid>
      <description>&lt;p&gt;The server returned a version banner string in the response content. Such information leaks may allow attackers to further target specific issues impacting the product and version in use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Private IP Disclosure</title>
      <link>/docs/alerts/2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/2/</guid>
      <description>&lt;p&gt;A private IP (such as 10.x.x.x, 172.x.x.x, 192.168.x.x) or an Amazon EC2 private hostname (for example, ip-10-0-56-78) has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Leaks Information via &#34;X-Powered-By&#34; HTTP Response Header Field(s)</title>
      <link>/docs/alerts/10037/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10037/</guid>
      <description>&lt;p&gt;The web/application server is leaking information via one or more &amp;ldquo;X-Powered-By&amp;rdquo; HTTP response headers. Access to such information may facilitate attackers identifying other frameworks/components your web application is reliant upon and the vulnerabilities such components may be subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Leaks its Webserver Application via &#34;Server&#34; HTTP Response Header Field</title>
      <link>/docs/alerts/10036-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10036-1/</guid>
      <description>&lt;p&gt;The web/application server is leaking the application it uses as a webserver via the &amp;ldquo;Server&amp;rdquo; HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server is subject to. This information alone, i.e. without a version string, is not very dangerous for the security of a server, nevertheless this information in the response header field is almost always useless and thus just an obsolete attacking vector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Leaks Version Information via &#34;Server&#34; HTTP Response Header Field</title>
      <link>/docs/alerts/10036-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10036-2/</guid>
      <description>&lt;p&gt;The web/application server is leaking version information via the &amp;ldquo;Server&amp;rdquo; HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server is subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Timestamp Disclosure - Unix</title>
      <link>/docs/alerts/10096/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10096/</guid>
      <description>&lt;p&gt;A timestamp was disclosed by the application/web server. - Unix&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Backend-Server Header Information Leak</title>
      <link>/docs/alerts/10039/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10039/</guid>
      <description>&lt;p&gt;The server is leaking information pertaining to backend systems (such as hostnames or IP addresses). Armed with this information an attacker may be able to attack other systems or more directly/efficiently attack those systems.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
