<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-642 on ZAP</title>
    <link>/alerttags/cwe-642/</link>
    <description>Recent content in CWE-642 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-642/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ASP.NET ViewState Integrity</title>
      <link>/docs/alerts/10094-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10094-2/</guid>
      <description>&lt;p&gt;The application does not use a Message Authentication Code (MAC) to protect the integrity of the ASP.NET ViewState, which can be tampered with by a malicious client.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Emails Found in the Viewstate</title>
      <link>/docs/alerts/10032-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-2/</guid>
      <description>&lt;p&gt;Email addresses were found being serialized in the viewstate field.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure JSF ViewState</title>
      <link>/docs/alerts/90001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90001/</guid>
      <description>&lt;p&gt;The response at the following URL contains a ViewState value that has no cryptographic protections.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Old Asp.Net Version in Use</title>
      <link>/docs/alerts/10032-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-3/</guid>
      <description>&lt;p&gt;This website uses ASP.NET version 1.0 or 1.1.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential IP Addresses Found in the Viewstate</title>
      <link>/docs/alerts/10032-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-1/</guid>
      <description>&lt;p&gt;Potential IP addresses were found being serialized in the viewstate field.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Split Viewstate in Use</title>
      <link>/docs/alerts/10032-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-6/</guid>
      <description>&lt;p&gt;This website uses ASP.NET&amp;rsquo;s Viewstate and its value is split into several chunks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Viewstate without MAC Signature (Sure)</title>
      <link>/docs/alerts/10032-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-5/</guid>
      <description>&lt;p&gt;This website uses ASP.NET&amp;rsquo;s Viewstate but without any MAC.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Viewstate without MAC Signature (Unsure)</title>
      <link>/docs/alerts/10032-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-4/</guid>
      <description>&lt;p&gt;This website uses ASP.NET&amp;rsquo;s Viewstate but maybe without any MAC.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
