<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>WSTG-V42-INFO-05 on ZAP</title>
    <link>/alerttags/wstg-v42-info-05/</link>
    <description>Recent content in WSTG-V42-INFO-05 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/wstg-v42-info-05/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Big Redirect Detected (Potential Sensitive Information Leak)</title>
      <link>/docs/alerts/10044-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10044-1/</guid>
      <description>&lt;p&gt;The server has responded with a redirect that seems to provide a large response. This may indicate that although the server sent a redirect it also responded with body content (which may include sensitive details, PII, etc.).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Image Exposes Location or Privacy Data</title>
      <link>/docs/alerts/10103/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10103/</guid>
      <description>&lt;p&gt;The image was found to contain embedded location information, such as GPS coordinates, or another privacy exposure, such as camera serial number.  Depending on the context of the image in the website, this information may expose private details of the users of a site.  For example, a site that allows users to upload profile pictures taken in the home may expose the home&amp;rsquo;s address.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Suspicious Comments</title>
      <link>/docs/alerts/10027/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10027/</guid>
      <description>&lt;p&gt;The response appears to contain suspicious comments which may help an attacker.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple HREFs Redirect Detected (Potential Sensitive Information Leak)</title>
      <link>/docs/alerts/10044-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10044-2/</guid>
      <description>&lt;p&gt;The server has responded with a redirect that seems to contain multiple links. This may indicate that although the server sent a redirect it also responded with body content links (which may include sensitive details, PII, lead to admin panels, etc.).&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-ChromeLogger-Data (XCOLD) Header Information Leak</title>
      <link>/docs/alerts/10052/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10052/</guid>
      <description>&lt;p&gt;The server is leaking information through the X-ChromeLogger-Data (or X-ChromePhp-Data) response header. The content of such headers can be customized by the developer, however it is not uncommon to find: server file system locations, vhost declarations, etc.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
