<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>TOOL_PTK on ZAP</title>
    <link>/alerttags/tool_ptk/</link>
    <description>Recent content in TOOL_PTK on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/tool_ptk/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>.NET stack trace / YSOD</title>
      <link>/docs/alerts/200010-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-3/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>access_token/id_token in URL</title>
      <link>/docs/alerts/200014-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200014-1/</guid>
      <description>&lt;p&gt;Detects access tokens, JWTs, and API keys present in URLs or query strings observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Admin/management path observed</title>
      <link>/docs/alerts/200019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-1/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Anchor href manipulated from tainted source</title>
      <link>/docs/alerts/210019-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-6/</guid>
      <description>&lt;p&gt;Tainted value assigned to href attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Android assetlinks.json observed</title>
      <link>/docs/alerts/200013-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-3/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from cookie</title>
      <link>/docs/alerts/210009-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-3/</guid>
      <description>&lt;p&gt;Cookie-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from form input</title>
      <link>/docs/alerts/210009-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-2/</guid>
      <description>&lt;p&gt;Form-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from localStorage</title>
      <link>/docs/alerts/210009-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-4/</guid>
      <description>&lt;p&gt;Storage-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from postMessage</title>
      <link>/docs/alerts/210009-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-5/</guid>
      <description>&lt;p&gt;postMessage-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression executed through Function constructor</title>
      <link>/docs/alerts/210009-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-1/</guid>
      <description>&lt;p&gt;Tainted data reached dynamic code execution while AngularJS expression parsing/compilation was active. This covers interpolation and $parse-style AngularJS expression injection cases.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - eval expression 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-24/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-24/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.0.1 to 1.1.5</title>
      <link>/docs/alerts/200021-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-2/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.0 to 1.2.18</title>
      <link>/docs/alerts/200021-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-5/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.19 to 1.2.23</title>
      <link>/docs/alerts/200021-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-10/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.24 to 1.2.26</title>
      <link>/docs/alerts/200021-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-12/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.27 to 1.3.20</title>
      <link>/docs/alerts/200021-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-13/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.6 to 1.2.18</title>
      <link>/docs/alerts/200021-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-8/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.4.0 to 1.4.5</title>
      <link>/docs/alerts/200021-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-15/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.4.2 to 1.5.8</title>
      <link>/docs/alerts/200021-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-17/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.6 and later</title>
      <link>/docs/alerts/200021-19/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-19/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - single-quote expression 1.2.19 to 1.2.23</title>
      <link>/docs/alerts/200021-20/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-20/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS interpolation delimiters in template string</title>
      <link>/docs/alerts/220004-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-5/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS ng-* expression attribute</title>
      <link>/docs/alerts/220004-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-6/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - alternate delimiters 1.6 and later</title>
      <link>/docs/alerts/200021-25/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-25/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - HTML entity alternate delimiters 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-23/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-23/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - HTML entity delimiters 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-22/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-22/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.0.1 to 1.1.5</title>
      <link>/docs/alerts/200021-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-1/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.0 to 1.2.1</title>
      <link>/docs/alerts/200021-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-4/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.19 to 1.2.23</title>
      <link>/docs/alerts/200021-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-9/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.2 to 1.2.5</title>
      <link>/docs/alerts/200021-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-6/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.24 to 1.2.29</title>
      <link>/docs/alerts/200021-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-11/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.6 to 1.2.18</title>
      <link>/docs/alerts/200021-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-7/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-14/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.5.0 to 1.5.8</title>
      <link>/docs/alerts/200021-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-16/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.6 and later</title>
      <link>/docs/alerts/200021-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-18/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected eval 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-21/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-21/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected short legacy 1.0.1 to 1.1.5</title>
      <link>/docs/alerts/200021-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-3/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>API docs endpoint observed</title>
      <link>/docs/alerts/200012-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-3/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>api_key/key in URL</title>
      <link>/docs/alerts/200014-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200014-3/</guid>
      <description>&lt;p&gt;Detects access tokens, JWTs, and API keys present in URLs or query strings observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple app-site-association observed</title>
      <link>/docs/alerts/200013-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-4/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid eval with string literals</title>
      <link>/docs/alerts/220003-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-3/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid execScript dynamic execution</title>
      <link>/docs/alerts/220003-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-2/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid Function constructor with strings</title>
      <link>/docs/alerts/220003-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-4/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid permissive regex origin checks</title>
      <link>/docs/alerts/220008-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-4/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid postMessage with wildcard targetOrigin</title>
      <link>/docs/alerts/220008-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-1/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid string-based timers</title>
      <link>/docs/alerts/220003-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-1/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid weak origin substring checks</title>
      <link>/docs/alerts/220008-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-3/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AWS Access Key ID pattern</title>
      <link>/docs/alerts/200011-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-2/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cache-Control public/max-age with Set-Cookie</title>
      <link>/docs/alerts/200018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200018/</guid>
      <description>&lt;p&gt;Flags potentially risky cacheability for responses that appear user-specific and missing cache partitioning indicators.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Clear-Site-Data present but missing executionContexts</title>
      <link>/docs/alerts/200005-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-17/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Clear-Site-Data uses wildcard *</title>
      <link>/docs/alerts/200005-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-18/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side redirect via history.pushState</title>
      <link>/docs/alerts/210015-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-4/</guid>
      <description>&lt;p&gt;Tainted URL passed to history.pushState, altering client-side navigation.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side redirect via location.assign</title>
      <link>/docs/alerts/210015-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-2/</guid>
      <description>&lt;p&gt;Tainted destination URL passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side redirect via location.href</title>
      <link>/docs/alerts/210015-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-1/</guid>
      <description>&lt;p&gt;Tainted data assigned to location.href, causing a client-side redirect.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side redirect via location.replace</title>
      <link>/docs/alerts/210015-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-3/</guid>
      <description>&lt;p&gt;Tainted destination URL passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side route change via history.replaceState</title>
      <link>/docs/alerts/210015-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-5/</guid>
      <description>&lt;p&gt;Tainted URL passed to history.replaceState, altering client-side navigation state.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud metadata IP referenced</title>
      <link>/docs/alerts/200016-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-4/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>COEP present but value is not &#39;require-corp&#39; or &#39;credentialless&#39;</title>
      <link>/docs/alerts/200005-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-14/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>COOP present but value is not &#39;same-origin&#39;</title>
      <link>/docs/alerts/200005-23/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-23/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>COOP set without COEP/CORP (incomplete cross-origin isolation)</title>
      <link>/docs/alerts/200005-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-13/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS allows any origin with credentials</title>
      <link>/docs/alerts/200005-19/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-19/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS allows broad headers</title>
      <link>/docs/alerts/200017-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200017-3/</guid>
      <description>&lt;p&gt;Adds passive CORS posture checks: missing Vary: Origin for dynamic ACAO, and permissive allowed headers/methods.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS allows broad methods</title>
      <link>/docs/alerts/200017-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200017-2/</guid>
      <description>&lt;p&gt;Adds passive CORS posture checks: missing Vary: Origin for dynamic ACAO, and permissive allowed headers/methods.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Credit Card Number</title>
      <link>/docs/alerts/200006-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200006-1/</guid>
      <description>&lt;p&gt;Sensitive data is anything that should not be accessible to admin access, known as sensitive data. Sensitive data may include personally identifiable information (PII), such as Social Security numbers, financial information, or login credentials. Sensitive Data Exposure occurs when an organization unknowingly exposes sensitive data or when a security incident leads to the accidental or unlawful destruction, loss, alteration, or admin disclosure of, or access to sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP &#39;frame-ancestors&#39; missing or overly broad</title>
      <link>/docs/alerts/200005-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-3/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP allows inline/eval or wildcards in script/style</title>
      <link>/docs/alerts/200005-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-2/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP Report-Only present without enforcing CSP</title>
      <link>/docs/alerts/200005-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-4/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to form action</title>
      <link>/docs/alerts/210006-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-3/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to formAction</title>
      <link>/docs/alerts/210006-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-4/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to formAction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to href</title>
      <link>/docs/alerts/210003-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-5/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to iframe.src</title>
      <link>/docs/alerts/210003-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-15/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to iframe.src.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to script.src</title>
      <link>/docs/alerts/210003-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-4/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to script.src and treated as executable content.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to src</title>
      <link>/docs/alerts/210003-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-7/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to a generic src attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL navigated via location.assign</title>
      <link>/docs/alerts/210003-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-10/</guid>
      <description>&lt;p&gt;Tainted data: URL passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL navigated via location.href</title>
      <link>/docs/alerts/210003-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-8/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to location.href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL navigated via location.replace</title>
      <link>/docs/alerts/210003-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-12/</guid>
      <description>&lt;p&gt;Tainted data: URL passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL opened via window.open</title>
      <link>/docs/alerts/210003-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-14/</guid>
      <description>&lt;p&gt;Tainted data: URL passed to window.open.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Debug/diagnostic path observed</title>
      <link>/docs/alerts/200019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-2/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deprecated Feature-Policy or unknown/overly-permissive Permissions-Policy</title>
      <link>/docs/alerts/200005-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-15/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow direct document.cookie assignment (incl. bracket access)</title>
      <link>/docs/alerts/220001-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220001-1/</guid>
      <description>&lt;p&gt;Detects cases where attacker-controlled DOM data is written into cookies (document.cookie or common wrapper functions). Can indicate session fixation, logic control, or preparation for exploit-chains.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow direct navigation primitives</title>
      <link>/docs/alerts/220002-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220002-1/</guid>
      <description>&lt;p&gt;Detects client-side code that can redirect users to attacker-controlled URLs (open redirects). Includes assignment/calls that control window/location/navigation, attr-based redirects, form actions and jQuery variants.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow document.write()/writeln()</title>
      <link>/docs/alerts/220000-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-3/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow innerHTML/outerHTML assignments</title>
      <link>/docs/alerts/220000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-1/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow insertAdjacentHTML()</title>
      <link>/docs/alerts/220000-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-7/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via document.write</title>
      <link>/docs/alerts/210000-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-5/</guid>
      <description>&lt;p&gt;Tainted data passed to document.write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via document.write (secondary sources)</title>
      <link>/docs/alerts/210017-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-4/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached document.write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via DOM mutation (secondary sources)</title>
      <link>/docs/alerts/210017-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-6/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached mutation sinks.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via DOM mutations</title>
      <link>/docs/alerts/210000-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-6/</guid>
      <description>&lt;p&gt;Tainted data inserted into the DOM via DOM mutation APIs.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via DOMParser.parseFromString</title>
      <link>/docs/alerts/210016-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-1/</guid>
      <description>&lt;p&gt;Tainted HTML parsed through DOMParser.parseFromString with an HTML-like MIME type.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Element.innerHTML</title>
      <link>/docs/alerts/210000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-2/</guid>
      <description>&lt;p&gt;Tainted data assigned to innerHTML (possible DOM XSS).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Element.outerHTML</title>
      <link>/docs/alerts/210000-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-3/</guid>
      <description>&lt;p&gt;Tainted data assigned to outerHTML (possible DOM XSS).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Element.setHTMLUnsafe</title>
      <link>/docs/alerts/210016-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-3/</guid>
      <description>&lt;p&gt;Tainted HTML passed to Element.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via iframe.srcdoc (secondary sources)</title>
      <link>/docs/alerts/210017-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-7/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached iframe.srcdoc.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via inline event handler</title>
      <link>/docs/alerts/210000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-1/</guid>
      <description>&lt;p&gt;Tainted data flowed into an inline event handler.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via inline handlers (secondary sources)</title>
      <link>/docs/alerts/210017-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-5/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached inline event handlers.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via innerHTML (Angular)</title>
      <link>/docs/alerts/220000-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-9/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via innerHTML (secondary sources)</title>
      <link>/docs/alerts/210017-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-1/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached innerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via insertAdjacentHTML</title>
      <link>/docs/alerts/210000-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-4/</guid>
      <description>&lt;p&gt;Tainted HTML passed into insertAdjacentHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via insertAdjacentHTML (secondary sources)</title>
      <link>/docs/alerts/210017-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-3/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached insertAdjacentHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via outerHTML (secondary sources)</title>
      <link>/docs/alerts/210017-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-2/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached outerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param attribute breakout</title>
      <link>/docs/alerts/200022-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-2/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param attribute-name event injection</title>
      <link>/docs/alerts/200022-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-11/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param double-quoted attribute event breakout</title>
      <link>/docs/alerts/200022-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-12/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param double-quoted resource onerror breakout</title>
      <link>/docs/alerts/200022-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-13/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param event-handler value</title>
      <link>/docs/alerts/200022-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-10/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param HTML image onerror</title>
      <link>/docs/alerts/200022-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-1/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param javascript: URL</title>
      <link>/docs/alerts/200022-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-17/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS block-comment breakout</title>
      <link>/docs/alerts/200022-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-8/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS double-quote breakout</title>
      <link>/docs/alerts/200022-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-3/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS expression execution</title>
      <link>/docs/alerts/200022-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-6/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS regex breakout</title>
      <link>/docs/alerts/200022-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-7/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS single-quote breakout</title>
      <link>/docs/alerts/200022-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-4/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS template literal breakout</title>
      <link>/docs/alerts/200022-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-5/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param script-tag breakout</title>
      <link>/docs/alerts/200022-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-9/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param single-quoted attribute event breakout</title>
      <link>/docs/alerts/200022-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-14/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param style-block breakout</title>
      <link>/docs/alerts/200022-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-18/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param SVG tag-name event injection</title>
      <link>/docs/alerts/200022-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-16/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param unquoted attribute event injection</title>
      <link>/docs/alerts/200022-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-15/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Range.createContextualFragment</title>
      <link>/docs/alerts/210016-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-2/</guid>
      <description>&lt;p&gt;Tainted HTML passed to Range.createContextualFragment.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via ShadowRoot.setHTMLUnsafe</title>
      <link>/docs/alerts/210016-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-4/</guid>
      <description>&lt;p&gt;Tainted HTML passed to ShadowRoot.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based Cookie Manipulation (taint flow)</title>
      <link>/docs/alerts/220001-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220001-2/</guid>
      <description>&lt;p&gt;Detects cases where attacker-controlled DOM data is written into cookies (document.cookie or common wrapper functions). Can indicate session fixation, logic control, or preparation for exploit-chains.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based JavaScript Injection (taint flow)</title>
      <link>/docs/alerts/220003-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-5/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based Link Manipulation (taint flow)</title>
      <link>/docs/alerts/220009-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220009-2/</guid>
      <description>&lt;p&gt;Detects DOM code that rewrites link destinations (href attributes) with attacker-controlled data. Manipulated links can mislead users into visiting malicious targets even if navigation is not forced automatically.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based Open Redirection (taint flow)</title>
      <link>/docs/alerts/220002-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220002-3/</guid>
      <description>&lt;p&gt;Detects client-side code that can redirect users to attacker-controlled URLs (open redirects). Includes assignment/calls that control window/location/navigation, attr-based redirects, form actions and jQuery variants.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based XSS (taint flow)</title>
      <link>/docs/alerts/220000-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-8/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic ACAO without Vary: Origin</title>
      <link>/docs/alerts/200017-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200017-1/</guid>
      <description>&lt;p&gt;Adds passive CORS posture checks: missing Vary: Origin for dynamic ACAO, and permissive allowed headers/methods.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic AngularJS $compile/$interpolate template</title>
      <link>/docs/alerts/220004-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-4/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic AngularJS $parse expression</title>
      <link>/docs/alerts/220004-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-3/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic code execution via eval</title>
      <link>/docs/alerts/210001-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210001-1/</guid>
      <description>&lt;p&gt;Tainted string executed via eval().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic code execution via Function constructor</title>
      <link>/docs/alerts/210001-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210001-2/</guid>
      <description>&lt;p&gt;Tainted string executed via Function constructor.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic code execution via Function.apply</title>
      <link>/docs/alerts/210001-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210001-3/</guid>
      <description>&lt;p&gt;Tainted string executed via Function.apply.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic template compilation</title>
      <link>/docs/alerts/220005-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-1/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Environment hints (dev/staging/test) in response</title>
      <link>/docs/alerts/200016-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-3/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Environment/config file observed</title>
      <link>/docs/alerts/200019-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-7/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>eval() from storage/referrer taint</title>
      <link>/docs/alerts/210018-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-1/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached eval().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via fetch headers</title>
      <link>/docs/alerts/210013-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-2/</guid>
      <description>&lt;p&gt;Tainted data sent in fetch() headers (e.g. Authorization, custom tokens).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via fetch URL</title>
      <link>/docs/alerts/210013-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-1/</guid>
      <description>&lt;p&gt;Tainted data used in fetch() URL, potentially exfiltrating sensitive information.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via image.src beacon</title>
      <link>/docs/alerts/210013-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-7/</guid>
      <description>&lt;p&gt;Tainted data embedded into image src URL for beacon-style exfiltration.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via navigator.sendBeacon</title>
      <link>/docs/alerts/210013-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-6/</guid>
      <description>&lt;p&gt;Tainted data sent via navigator.sendBeacon().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest body</title>
      <link>/docs/alerts/210013-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-4/</guid>
      <description>&lt;p&gt;Tainted data sent in XMLHttpRequest.send() body.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest headers</title>
      <link>/docs/alerts/210013-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-5/</guid>
      <description>&lt;p&gt;Tainted data sent in XMLHttpRequest.setRequestHeader() values.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest URL</title>
      <link>/docs/alerts/210013-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-3/</guid>
      <description>&lt;p&gt;Tainted data used in XMLHttpRequest.open() URL.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Expect-CT is deprecated</title>
      <link>/docs/alerts/200005-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-12/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposure of Git repository</title>
      <link>/docs/alerts/200004-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200004-1/</guid>
      <description>&lt;p&gt;Version control repositories such as CVS or git store version-specific metadata and other details within subdirectories. If these subdirectories are stored on a web server or added to an archive, then these could be used by an attacker. This information may include usernames, filenames, path root, IP addresses, and detailed &amp;lsquo;diff&amp;rsquo; data about how files have been changed - which could reveal source code snippets that were never intended to be made public..&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposure of Mercurial repository</title>
      <link>/docs/alerts/200004-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200004-3/</guid>
      <description>&lt;p&gt;Version control repositories such as CVS or git store version-specific metadata and other details within subdirectories. If these subdirectories are stored on a web server or added to an archive, then these could be used by an attacker. This information may include usernames, filenames, path root, IP addresses, and detailed &amp;lsquo;diff&amp;rsquo; data about how files have been changed - which could reveal source code snippets that were never intended to be made public..&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposure of SVN repository</title>
      <link>/docs/alerts/200004-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200004-2/</guid>
      <description>&lt;p&gt;Version control repositories such as CVS or git store version-specific metadata and other details within subdirectories. If these subdirectories are stored on a web server or added to an archive, then these could be used by an attacker. This information may include usernames, filenames, path root, IP addresses, and detailed &amp;lsquo;diff&amp;rsquo; data about how files have been changed - which could reveal source code snippets that were never intended to be made public..&lt;/p&gt;</description>
    </item>
    <item>
      <title>File/path candidate parameter</title>
      <link>/docs/alerts/200015-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-3/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Firebase config exposed</title>
      <link>/docs/alerts/200011-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-6/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Form action manipulated by tainted route or body input</title>
      <link>/docs/alerts/210005-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210005-1/</guid>
      <description>&lt;p&gt;Tainted route, body, or messaging value changed form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Form action manipulated from tainted source</title>
      <link>/docs/alerts/210019-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-7/</guid>
      <description>&lt;p&gt;Tainted value assigned to form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>formAction manipulated by tainted route or body input</title>
      <link>/docs/alerts/210005-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210005-2/</guid>
      <description>&lt;p&gt;Tainted route, body, or messaging value changed formAction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Function.apply() from storage/referrer taint</title>
      <link>/docs/alerts/210018-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-3/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached Function.apply().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Function() from storage/referrer taint</title>
      <link>/docs/alerts/210018-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-2/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached Function constructor.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitHub token pattern</title>
      <link>/docs/alerts/200011-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-4/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Google API key pattern</title>
      <link>/docs/alerts/200011-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-9/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphiQL / GraphQL Playground detected</title>
      <link>/docs/alerts/200012-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-5/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL endpoint observed</title>
      <link>/docs/alerts/200012-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-4/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL path observed</title>
      <link>/docs/alerts/200019-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-5/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>HSTS max-age too low or missing includeSubDomains</title>
      <link>/docs/alerts/200005-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-7/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTML references .map files</title>
      <link>/docs/alerts/200009-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-2/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>IDOR candidate parameter</title>
      <link>/docs/alerts/200015-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-4/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>IFrame content injection via srcdoc</title>
      <link>/docs/alerts/210012-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210012-2/</guid>
      <description>&lt;p&gt;Tainted HTML assigned to iframe.srcdoc, enabling DOM-based XSS inside the frame.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>IFrame navigation via src</title>
      <link>/docs/alerts/210012-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210012-1/</guid>
      <description>&lt;p&gt;Tainted URL assigned to iframe.src, causing navigation to untrusted content.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Inline event handler built from dynamic data</title>
      <link>/docs/alerts/220000-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-6/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Internal file path disclosure</title>
      <link>/docs/alerts/200010-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-6/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Internal IP address leaked in response</title>
      <link>/docs/alerts/200016-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-1/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Java stack trace</title>
      <link>/docs/alerts/200010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-2/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JavaScript includes sourceMappingURL</title>
      <link>/docs/alerts/200009-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-1/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to form action</title>
      <link>/docs/alerts/210006-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-1/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to formAction</title>
      <link>/docs/alerts/210006-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-2/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to formAction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to href</title>
      <link>/docs/alerts/210003-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-1/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to href and likely to execute in the current browsing context.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to iframe.src</title>
      <link>/docs/alerts/210003-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-3/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to iframe.src.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to src</title>
      <link>/docs/alerts/210003-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-6/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to a generic src attribute and interpreted as executable content.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL navigated via location.assign</title>
      <link>/docs/alerts/210003-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-9/</guid>
      <description>&lt;p&gt;Tainted javascript: URL passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL navigated via location.href</title>
      <link>/docs/alerts/210003-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-2/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to location.href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL navigated via location.replace</title>
      <link>/docs/alerts/210003-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-11/</guid>
      <description>&lt;p&gt;Tainted javascript: URL passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL opened via window.open</title>
      <link>/docs/alerts/210003-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-13/</guid>
      <description>&lt;p&gt;Tainted javascript: URL passed to window.open.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JSONP callback parameter controls JavaScript response</title>
      <link>/docs/alerts/200024/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200024/</guid>
      <description>&lt;p&gt;Tests callback-like parameters for JSONP-style JavaScript responses where user input controls the executed callback name.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Authorization header)</title>
      <link>/docs/alerts/200003-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-6/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Cookie)</title>
      <link>/docs/alerts/200003-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-4/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Form body param)</title>
      <link>/docs/alerts/200003-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-5/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (JSON body)</title>
      <link>/docs/alerts/200003-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-7/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (Authorization &#43; JWT cookies removed)</title>
      <link>/docs/alerts/200003-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-1/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (Authorization header removed)</title>
      <link>/docs/alerts/200003-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-2/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (JWT cookies removed)</title>
      <link>/docs/alerts/200003-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-3/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT-like value in URL</title>
      <link>/docs/alerts/200014-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200014-2/</guid>
      <description>&lt;p&gt;Detects access tokens, JWTs, and API keys present in URLs or query strings observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lit unsafeHTML taint flow</title>
      <link>/docs/alerts/220005-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-6/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>localhost/127.0.0.1 referenced in response</title>
      <link>/docs/alerts/200016-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-2/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>location.assign redirect from tainted source</title>
      <link>/docs/alerts/210019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-2/</guid>
      <description>&lt;p&gt;Tainted value passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>location.href redirect from tainted source</title>
      <link>/docs/alerts/210019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-1/</guid>
      <description>&lt;p&gt;Tainted value navigated location.href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>location.replace redirect from tainted source</title>
      <link>/docs/alerts/210019-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-3/</guid>
      <description>&lt;p&gt;Tainted value passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mapbox token exposed</title>
      <link>/docs/alerts/200011-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-8/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Message handler without origin validation</title>
      <link>/docs/alerts/220008-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-7/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing Content-Security-Policy header</title>
      <link>/docs/alerts/200005-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-1/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing or invalid X-Content-Type-Options</title>
      <link>/docs/alerts/200005-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-10/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing or weak Referrer-Policy</title>
      <link>/docs/alerts/200005-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-16/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing Strict-Transport-Security header (on HTTPS)</title>
      <link>/docs/alerts/200005-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-5/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>navigation.navigate redirect from tainted source</title>
      <link>/docs/alerts/210019-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-5/</guid>
      <description>&lt;p&gt;Tainted value passed to navigation.navigate.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Next.js build metadata exposed</title>
      <link>/docs/alerts/200009-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-4/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Node.js / Express stack trace</title>
      <link>/docs/alerts/200010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-1/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>OIDC well-known configuration observed</title>
      <link>/docs/alerts/200013-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-2/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect candidate parameter</title>
      <link>/docs/alerts/200015-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-1/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect reflected in body destination</title>
      <link>/docs/alerts/200023-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200023-3/</guid>
      <description>&lt;p&gt;Tests for open redirect by forcing redirect-like parameters to an external, benign domain.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect reflected in form action</title>
      <link>/docs/alerts/200023-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200023-2/</guid>
      <description>&lt;p&gt;Tests for open redirect by forcing redirect-like parameters to an external, benign domain.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect via common param names</title>
      <link>/docs/alerts/200023-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200023-1/</guid>
      <description>&lt;p&gt;Tests for open redirect by forcing redirect-like parameters to an external, benign domain.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect via Navigation API</title>
      <link>/docs/alerts/210002-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210002-2/</guid>
      <description>&lt;p&gt;Tainted destination URL used in navigation.navigate.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect via window.open</title>
      <link>/docs/alerts/210002-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210002-1/</guid>
      <description>&lt;p&gt;Tainted URL used in window.open (possible open redirect).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>OpenAPI spec detected</title>
      <link>/docs/alerts/200012-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-2/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Origin check uses host fragment only</title>
      <link>/docs/alerts/220008-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-5/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>OS Command Injection - Unix cat /etc/passwd (pipe)</title>
      <link>/docs/alerts/200001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200001/</guid>
      <description>&lt;p&gt;OS command injection (also known as shell injection) is a web security vulnerability that allows an attacker to execute arbitrary operating system (OS) commands on the server that is running an application, and typically fully compromise the application and all its data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>PHP fatal error / warning</title>
      <link>/docs/alerts/200010-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-5/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>phpinfo endpoint observed</title>
      <link>/docs/alerts/200019-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-9/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>postMessage to cross-origin target with tainted payload</title>
      <link>/docs/alerts/210010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210010-2/</guid>
      <description>&lt;p&gt;Tainted data sent via window.postMessage to a different origin.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>postMessage to wildcard origin with tainted payload</title>
      <link>/docs/alerts/210010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210010-1/</guid>
      <description>&lt;p&gt;Tainted data sent via window.postMessage to wildcard &amp;lsquo;*&amp;rsquo; targetOrigin.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential .git exposure path observed</title>
      <link>/docs/alerts/200019-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-8/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential backup file observed</title>
      <link>/docs/alerts/200019-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-6/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potentially authenticated content lacks no-store</title>
      <link>/docs/alerts/200005-21/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-21/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Private key material exposed</title>
      <link>/docs/alerts/200011-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-1/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Prototype pollution influenced fetch() init</title>
      <link>/docs/alerts/210008-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210008-1/</guid>
      <description>&lt;p&gt;A prior tainted prototype write influenced inherited fetch() init fields.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Public-Key-Pins is deprecated</title>
      <link>/docs/alerts/200005-22/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-22/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Python traceback</title>
      <link>/docs/alerts/200010-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-4/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>React dangerouslySetInnerHTML taint flow</title>
      <link>/docs/alerts/220005-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-5/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field parsed via createContextualFragment</title>
      <link>/docs/alerts/210007-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-7/</guid>
      <description>&lt;p&gt;Response-derived HTML parsed via Range.createContextualFragment.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field parsed via DOMParser</title>
      <link>/docs/alerts/210007-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-6/</guid>
      <description>&lt;p&gt;Response-derived HTML parsed via DOMParser.parseFromString.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via document.write</title>
      <link>/docs/alerts/210007-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-2/</guid>
      <description>&lt;p&gt;Response-derived data reached document.write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via DOM mutation</title>
      <link>/docs/alerts/210007-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-5/</guid>
      <description>&lt;p&gt;Response-derived data reached DOM mutation sinks.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via innerHTML</title>
      <link>/docs/alerts/210007-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-1/</guid>
      <description>&lt;p&gt;Response-derived data reached innerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via insertAdjacentHTML</title>
      <link>/docs/alerts/210007-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-4/</guid>
      <description>&lt;p&gt;Response-derived HTML reached insertAdjacentHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via outerHTML</title>
      <link>/docs/alerts/210007-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-3/</guid>
      <description>&lt;p&gt;Response-derived data reached outerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via setHTMLUnsafe</title>
      <link>/docs/alerts/210007-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-8/</guid>
      <description>&lt;p&gt;Response-derived HTML reached Element.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via ShadowRoot.setHTMLUnsafe</title>
      <link>/docs/alerts/210007-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-9/</guid>
      <description>&lt;p&gt;Response-derived HTML reached ShadowRoot.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review assignments to href/src/action</title>
      <link>/docs/alerts/220009-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220009-1/</guid>
      <description>&lt;p&gt;Detects DOM code that rewrites link destinations (href attributes) with attacker-controlled data. Manipulated links can mislead users into visiting malicious targets even if navigation is not forced automatically.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review direct Axios destination usage</title>
      <link>/docs/alerts/220006-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-4/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review DOMParser.parseFromString with dynamic HTML/XML</title>
      <link>/docs/alerts/220000-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-4/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review dynamic import usage</title>
      <link>/docs/alerts/220007-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-3/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review EventSource constructor usage</title>
      <link>/docs/alerts/220006-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-3/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review importScripts usage</title>
      <link>/docs/alerts/220007-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-7/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review jQuery getScript usage</title>
      <link>/docs/alerts/220007-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-1/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review message event listeners</title>
      <link>/docs/alerts/220008-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-6/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review sendBeacon body content</title>
      <link>/docs/alerts/220006-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-2/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review sendBeacon destination</title>
      <link>/docs/alerts/220006-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-1/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review serviceWorker.register usage</title>
      <link>/docs/alerts/220007-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-6/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review SharedWorker constructor usage</title>
      <link>/docs/alerts/220007-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-5/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review System.import usage</title>
      <link>/docs/alerts/220007-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-2/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review uses of appendChild</title>
      <link>/docs/alerts/220000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-2/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review Vue v-html template usage</title>
      <link>/docs/alerts/220005-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-3/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review Worker constructor usage</title>
      <link>/docs/alerts/220007-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-4/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Route-controlled history.pushState</title>
      <link>/docs/alerts/210004-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210004-3/</guid>
      <description>&lt;p&gt;Client route state influenced history.pushState.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Route-controlled history.replaceState</title>
      <link>/docs/alerts/210004-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210004-1/</guid>
      <description>&lt;p&gt;Client route state influenced history.replaceState.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Route-controlled Navigation API transition</title>
      <link>/docs/alerts/210004-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210004-2/</guid>
      <description>&lt;p&gt;Client route state influenced navigation.navigate.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Same-origin URL mutations</title>
      <link>/docs/alerts/220002-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220002-2/</guid>
      <description>&lt;p&gt;Detects client-side code that can redirect users to attacker-controlled URLs (open redirects). Includes assignment/calls that control window/location/navigation, attr-based redirects, form actions and jQuery variants.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>security.txt observed</title>
      <link>/docs/alerts/200013-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-1/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sensitive cookies missing security flags</title>
      <link>/docs/alerts/200005-20/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-20/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sentry DSN exposed</title>
      <link>/docs/alerts/200011-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-5/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server banner discloses software/version</title>
      <link>/docs/alerts/200005-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-9/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>setInterval(string) from storage/referrer taint</title>
      <link>/docs/alerts/210018-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-5/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached setInterval(string).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>setTimeout(string) from storage/referrer taint</title>
      <link>/docs/alerts/210018-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-4/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached setTimeout(string).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Slack token pattern</title>
      <link>/docs/alerts/200011-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-3/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Social Security Number</title>
      <link>/docs/alerts/200006-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200006-2/</guid>
      <description>&lt;p&gt;Sensitive data is anything that should not be accessible to admin access, known as sensitive data. Sensitive data may include personally identifiable information (PII), such as Social Security numbers, financial information, or login credentials. Sensitive Data Exposure occurs when an organization unknowingly exposes sensitive data or when a security incident leads to the accidental or unlawful destruction, loss, alteration, or admin disclosure of, or access to sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SPA hash DOM XSS</title>
      <link>/docs/alerts/200007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200007/</guid>
      <description>&lt;p&gt;Tests hash-based SPA parameters (http://host/#/route?param=&amp;hellip;) for DOM XSS by mutating the hash in a dedicated attack tab and inspecting the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Specify postMessage targetOrigin</title>
      <link>/docs/alerts/220008-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-2/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spring Boot actuator endpoint observed</title>
      <link>/docs/alerts/200019-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-3/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Double Quote (after)</title>
      <link>/docs/alerts/200000-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-4/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Double Quote (before)</title>
      <link>/docs/alerts/200000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-2/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Single Quote (after)</title>
      <link>/docs/alerts/200000-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-3/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Single Quote (before)</title>
      <link>/docs/alerts/200000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-1/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SSRF / webhook URL candidate parameter</title>
      <link>/docs/alerts/200015-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-2/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security sent over HTTP (ineffective)</title>
      <link>/docs/alerts/200005-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-6/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Stripe publishable key exposed</title>
      <link>/docs/alerts/200011-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-7/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Swagger UI detected</title>
      <link>/docs/alerts/200012-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-1/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Swagger/OpenAPI path observed</title>
      <link>/docs/alerts/200019-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-4/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted dangerous key used in prototype write</title>
      <link>/docs/alerts/210008-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210008-2/</guid>
      <description>&lt;p&gt;Tainted data reached a dangerous prototype key write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted data compiled as AngularJS template</title>
      <link>/docs/alerts/220004-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-2/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted data passed to AngularJS $parse</title>
      <link>/docs/alerts/220004-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-1/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted network destination URL</title>
      <link>/docs/alerts/220006-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-5/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted string executed via setInterval</title>
      <link>/docs/alerts/210011-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210011-2/</guid>
      <description>&lt;p&gt;Tainted string passed as the first argument to setInterval(), leading to repeated code execution.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted string executed via setTimeout</title>
      <link>/docs/alerts/210011-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210011-1/</guid>
      <description>&lt;p&gt;Tainted string passed as the first argument to setTimeout(), leading to code execution.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to element.href</title>
      <link>/docs/alerts/210014-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-1/</guid>
      <description>&lt;p&gt;Tainted URL assigned to an element href attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to element.src</title>
      <link>/docs/alerts/210014-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-2/</guid>
      <description>&lt;p&gt;Tainted URL assigned to a non-script/iframe/src element src attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to form action</title>
      <link>/docs/alerts/210014-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-3/</guid>
      <description>&lt;p&gt;Tainted URL assigned to a form action attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to formAction</title>
      <link>/docs/alerts/210014-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-4/</guid>
      <description>&lt;p&gt;Tainted URL assigned to a formAction attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted worker or script loader URL</title>
      <link>/docs/alerts/220007-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-8/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Template injection (taint flow)</title>
      <link>/docs/alerts/220005-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-4/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Template output injected into DOM</title>
      <link>/docs/alerts/220005-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-2/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>template.innerHTML with dynamic content</title>
      <link>/docs/alerts/220000-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-5/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted DOM data into createHTMLDocument</title>
      <link>/docs/alerts/220010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220010-2/</guid>
      <description>&lt;p&gt;Detects untrusted DOM data being written into form metadata (formAction/target/method/value/placeholder), inline style surfaces (style/cssText/background*), document.title, history state, or createHTMLDocument — mutations that influence UI/navigation state without covering classic href/src/action sinks already handled elsewhere.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted DOM data into navigation-adjacent sinks</title>
      <link>/docs/alerts/220010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220010-1/</guid>
      <description>&lt;p&gt;Detects untrusted DOM data being written into form metadata (formAction/target/method/value/placeholder), inline style surfaces (style/cssText/background*), document.title, history state, or createHTMLDocument — mutations that influence UI/navigation state without covering classic href/src/action sinks already handled elsewhere.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted DOM data into UI mutation sinks</title>
      <link>/docs/alerts/220010-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220010-3/</guid>
      <description>&lt;p&gt;Detects untrusted DOM data being written into form metadata (formAction/target/method/value/placeholder), inline style surfaces (style/cssText/background*), document.title, history state, or createHTMLDocument — mutations that influence UI/navigation state without covering classic href/src/action sinks already handled elsewhere.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web Message Injection (taint flow)</title>
      <link>/docs/alerts/220008-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-9/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webpack dev-server / hot reload artifacts</title>
      <link>/docs/alerts/200009-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-3/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wildcard reply from message handler</title>
      <link>/docs/alerts/220008-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-8/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>window.open redirect from tainted source</title>
      <link>/docs/alerts/210019-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-4/</guid>
      <description>&lt;p&gt;Tainted value passed to window.open.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>ws:// from HTTPS context</title>
      <link>/docs/alerts/200008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200008/</guid>
      <description>&lt;p&gt;Looks for common WebSocket endpoints and insecure patterns such as ws:// from HTTPS pages.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Powered-By header or equivalent present</title>
      <link>/docs/alerts/200005-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-8/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-XSS-Protection header is a legacy directive</title>
      <link>/docs/alerts/200005-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-11/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - attribute context img onerror</title>
      <link>/docs/alerts/200002-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-6/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - attribute-name event injection</title>
      <link>/docs/alerts/200002-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-17/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - double-quoted attribute event injection</title>
      <link>/docs/alerts/200002-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-14/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Img onerror</title>
      <link>/docs/alerts/200002-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-4/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Img onerror</title>
      <link>/docs/alerts/200002-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-5/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS block comment break-out</title>
      <link>/docs/alerts/200002-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-13/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS expression replacement</title>
      <link>/docs/alerts/200002-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-10/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS single-quoted string break-out</title>
      <link>/docs/alerts/200002-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-11/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS slash/regex literal break-out</title>
      <link>/docs/alerts/200002-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-12/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS string break-out</title>
      <link>/docs/alerts/200002-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-8/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS template literal break-out</title>
      <link>/docs/alerts/200002-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-9/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Script tag after noscript tag</title>
      <link>/docs/alerts/200002-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-2/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - single-quoted attribute event injection</title>
      <link>/docs/alerts/200002-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-15/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - SVG onload polyglot</title>
      <link>/docs/alerts/200002-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-7/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Svg tag with animation event</title>
      <link>/docs/alerts/200002-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-3/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - tag-name SVG onload injection</title>
      <link>/docs/alerts/200002-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-18/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Unfiltered &lt;script&gt; tag</title>
      <link>/docs/alerts/200002-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-1/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - unquoted attribute event injection</title>
      <link>/docs/alerts/200002-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-16/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
