<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>WSTG-V42-CONF-05 on ZAP</title>
    <link>/alerttags/wstg-v42-conf-05/</link>
    <description>Recent content in WSTG-V42-CONF-05 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/wstg-v42-conf-05/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>.env Information Leak</title>
      <link>/docs/alerts/40034/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40034/</guid>
      <description>&lt;p&gt;One or more .env files seems to have been located on the server. These files often expose infrastructure or administrative account credentials, API or APP keys, or other sensitive configuration information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>.htaccess Information Leak</title>
      <link>/docs/alerts/40032/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40032/</guid>
      <description>&lt;p&gt;htaccess files can be used to alter the configuration of the Apache Web Server software to enable/disable additional functionality and features that the Apache Web Server software has to offer.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ELMAH Information Leak</title>
      <link>/docs/alerts/40028/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40028/</guid>
      <description>&lt;p&gt;The Error Logging Modules and Handlers (ELMAH [elmah.axd]) HTTP Module was found to be available. This module can leak a significant amount of valuable information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hidden File Found</title>
      <link>/docs/alerts/40035/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40035/</guid>
      <description>&lt;p&gt;A sensitive file was identified as accessible or available. This may leak administrative, configuration, or credential information which can be leveraged by a malicious individual to further attack the system or conduct social engineering efforts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Properties File Disclosure - /WEB-INF folder</title>
      <link>/docs/alerts/10045-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10045-2/</guid>
      <description>&lt;p&gt;A Java class in the /WEB-INF folder disclosed the presence of the properties file. Properties file are not intended to be publicly accessible, and typically contain configuration information, application credentials, or cryptographic keys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - /WEB-INF Folder</title>
      <link>/docs/alerts/10045-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10045-1/</guid>
      <description>&lt;p&gt;Java source code was disclosed by the web server in Java class files in the WEB-INF folder. The class files can be dis-assembled to produce source code which very closely matches the original source code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spring Actuator Information Leak</title>
      <link>/docs/alerts/40042/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40042/</guid>
      <description>&lt;p&gt;Spring Actuator for Health is enabled and may reveal sensitive information about this application. Spring Actuators can be used for real monitoring purposes, but should be used with caution as to not expose too much information about the application or the infrastructure running it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Trace.axd Information Leak</title>
      <link>/docs/alerts/40029/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40029/</guid>
      <description>&lt;p&gt;The ASP.NET Trace Viewer (trace.axd) was found to be available. This component can leak a significant amount of valuable information.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
