<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ZAP Alert Details on ZAP</title>
    <link>/docs/alerts/</link>
    <description>Recent content in ZAP Alert Details on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 24 Jan 2024 15:42:00 +0000</lastBuildDate>
    <atom:link href="/docs/alerts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Apache Range Header DoS (CVE-2011-3192)</title>
      <link>/docs/alerts/10053/</link>
      <pubDate>Mon, 02 Nov 2020 15:05:54 +0000</pubDate>
      <guid>/docs/alerts/10053/</guid>
      <description>&lt;p&gt;The byterange filter in earlier versions of the Apache HTTP Server allows remote attackers to cause a denial of service (memory and CPU exhaustion) via a Range request header that identifies multiple overlapping ranges. This issue was exploited in the wild in August 2011.&lt;/p&gt;&#xA;&#xA;&lt;h2 id=&#34;deprecated-2020-06-13&#34;&gt;Deprecated: 2020-06-13 &lt;a class=&#34;header-link&#34; href=&#34;#deprecated-2020-06-13&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Produced too many false positives and is no longer relevant.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure Component</title>
      <link>/docs/alerts/10046/</link>
      <pubDate>Fri, 30 Oct 2020 12:12:42 +0000</pubDate>
      <guid>/docs/alerts/10046/</guid>
      <description>&lt;p&gt;Based on passive analysis of the response, insecure component {0} {1} appears to be in use.&#xA;The highest noted CVSS rating for this product version is {2}.&#xA;In total, {3} vulnerabilities were noted.&#xA;Some Linux distributions such as Red Hat employ the practice of retaining old version numbers when security fixes are &amp;ldquo;backported&amp;rdquo;.&#xA;These cases are noted as &amp;ldquo;False Positives&amp;rdquo;, but should be manually verified.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web Browser XSS Protection Not Enabled</title>
      <link>/docs/alerts/10016/</link>
      <pubDate>Fri, 30 Oct 2020 12:12:42 +0000</pubDate>
      <guid>/docs/alerts/10016/</guid>
      <description>&lt;p&gt;Web Browser XSS Protection is not enabled, or is disabled by the configuration of the &amp;lsquo;X-XSS-Protection&amp;rsquo; HTTP response header on the web server&lt;/p&gt;&#xA;&#xA;&lt;h2 id=&#34;deprecated-2020-02-11&#34;&gt;Deprecated: 2020-02-11 &lt;a class=&#34;header-link&#34; href=&#34;#deprecated-2020-02-11&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;No longer widely supported by browsers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>.env Information Leak</title>
      <link>/docs/alerts/40034/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40034/</guid>
      <description>&lt;p&gt;One or more .env files seems to have been located on the server. These files often expose infrastructure or administrative account credentials, API or APP keys, or other sensitive configuration information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>.htaccess Information Leak</title>
      <link>/docs/alerts/40032/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40032/</guid>
      <description>&lt;p&gt;htaccess files can be used to alter the configuration of the Apache Web Server software to enable/disable additional functionality and features that the Apache Web Server software has to offer.&lt;/p&gt;</description>
    </item>
    <item>
      <title>.NET stack trace / YSOD</title>
      <link>/docs/alerts/200010-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-3/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Client Error response code was returned by the server</title>
      <link>/docs/alerts/100000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100000-1/</guid>
      <description>&lt;p&gt;A response code of 400 was returned by the server.&#xA;This may indicate that the application is failing to handle unexpected input correctly.&#xA;Raised by the &amp;lsquo;Alert on HTTP Response Code Error&amp;rsquo; script&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Server Error response code was returned by the server</title>
      <link>/docs/alerts/100000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100000-2/</guid>
      <description>&lt;p&gt;A response code of 500 was returned by the server.&#xA;This may indicate that the application is failing to handle unexpected input correctly.&#xA;Raised by the &amp;lsquo;Alert on HTTP Response Code Error&amp;rsquo; script&lt;/p&gt;</description>
    </item>
    <item>
      <title>Absence of Anti-CSRF Tokens</title>
      <link>/docs/alerts/10202/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10202/</guid>
      <description>&lt;p&gt;No Anti-CSRF tokens were found in a HTML submission form.&#xA;A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Access Control Issue - Improper Authentication</title>
      <link>/docs/alerts/10101/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10101/</guid>
      <description>&lt;p&gt;Insufficient Authentication occurs when a web site permits an attacker to access sensitive content or functionality without having to properly authenticate. Web-based administration tools are a good example of web sites providing access to sensitive functionality. Depending on the specific online resource, these web applications should not be directly accessible without requiring the user to properly verify their identity.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Access Control Issue - Improper Authorization</title>
      <link>/docs/alerts/10102/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10102/</guid>
      <description>&lt;p&gt;Insufficient Authorization results when an application does not perform adequate authorization checks to ensure that the user is performing a function or accessing data in a manner consistent with the security policy. Authorization procedures should enforce what a user, service or application is permitted to do. When a user is authenticated to a web site, it does not necessarily mean that the user should have full access to all content and functionality.&lt;/p&gt;</description>
    </item>
    <item>
      <title>access_token/id_token in URL</title>
      <link>/docs/alerts/200014-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200014-1/</guid>
      <description>&lt;p&gt;Detects access tokens, JWTs, and API keys present in URLs or query strings observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Admin/management path observed</title>
      <link>/docs/alerts/200019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-1/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Advanced SQL Injection</title>
      <link>/docs/alerts/90018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90018/</guid>
      <description>&lt;p&gt;A SQL injection may be possible using the attached payload.&lt;/p&gt;</description>
    </item>
    <item>
      <title>An Error response code was returned by the server</title>
      <link>/docs/alerts/100000/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100000/</guid>
      <description></description>
    </item>
    <item>
      <title>Anchor href manipulated from tainted source</title>
      <link>/docs/alerts/210019-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-6/</guid>
      <description>&lt;p&gt;Tainted value assigned to href attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Android assetlinks.json observed</title>
      <link>/docs/alerts/200013-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-3/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from cookie</title>
      <link>/docs/alerts/210009-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-3/</guid>
      <description>&lt;p&gt;Cookie-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from form input</title>
      <link>/docs/alerts/210009-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-2/</guid>
      <description>&lt;p&gt;Form-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from localStorage</title>
      <link>/docs/alerts/210009-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-4/</guid>
      <description>&lt;p&gt;Storage-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS $parse expression from postMessage</title>
      <link>/docs/alerts/210009-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-5/</guid>
      <description>&lt;p&gt;postMessage-controlled expression value reaches AngularJS $parse.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS client-side template / expression injection</title>
      <link>/docs/alerts/200021/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021/</guid>
      <description></description>
    </item>
    <item>
      <title>AngularJS client-side template / expression injection</title>
      <link>/docs/alerts/220004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004/</guid>
      <description></description>
    </item>
    <item>
      <title>AngularJS expression / client-template injection</title>
      <link>/docs/alerts/210009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009/</guid>
      <description></description>
    </item>
    <item>
      <title>AngularJS expression executed through Function constructor</title>
      <link>/docs/alerts/210009-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210009-1/</guid>
      <description>&lt;p&gt;Tainted data reached dynamic code execution while AngularJS expression parsing/compilation was active. This covers interpolation and $parse-style AngularJS expression injection cases.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - eval expression 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-24/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-24/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.0.1 to 1.1.5</title>
      <link>/docs/alerts/200021-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-2/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.0 to 1.2.18</title>
      <link>/docs/alerts/200021-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-5/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.19 to 1.2.23</title>
      <link>/docs/alerts/200021-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-10/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.24 to 1.2.26</title>
      <link>/docs/alerts/200021-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-12/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.27 to 1.3.20</title>
      <link>/docs/alerts/200021-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-13/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.2.6 to 1.2.18</title>
      <link>/docs/alerts/200021-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-8/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.4.0 to 1.4.5</title>
      <link>/docs/alerts/200021-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-15/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.4.2 to 1.5.8</title>
      <link>/docs/alerts/200021-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-17/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - expression 1.6 and later</title>
      <link>/docs/alerts/200021-19/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-19/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS expression injection - single-quote expression 1.2.19 to 1.2.23</title>
      <link>/docs/alerts/200021-20/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-20/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS interpolation delimiters in template string</title>
      <link>/docs/alerts/220004-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-5/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS ng-* expression attribute</title>
      <link>/docs/alerts/220004-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-6/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - alternate delimiters 1.6 and later</title>
      <link>/docs/alerts/200021-25/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-25/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - HTML entity alternate delimiters 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-23/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-23/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - HTML entity delimiters 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-22/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-22/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.0.1 to 1.1.5</title>
      <link>/docs/alerts/200021-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-1/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.0 to 1.2.1</title>
      <link>/docs/alerts/200021-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-4/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.19 to 1.2.23</title>
      <link>/docs/alerts/200021-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-9/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.2 to 1.2.5</title>
      <link>/docs/alerts/200021-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-6/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.24 to 1.2.29</title>
      <link>/docs/alerts/200021-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-11/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.2.6 to 1.2.18</title>
      <link>/docs/alerts/200021-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-7/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-14/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.5.0 to 1.5.8</title>
      <link>/docs/alerts/200021-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-16/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected 1.6 and later</title>
      <link>/docs/alerts/200021-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-18/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected eval 1.4.0 to 1.4.9</title>
      <link>/docs/alerts/200021-21/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-21/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AngularJS template injection - reflected short legacy 1.0.1 to 1.1.5</title>
      <link>/docs/alerts/200021-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200021-3/</guid>
      <description>&lt;p&gt;Detects AngularJS client-side template and expression injection by sending version-gated AngularJS sandbox-escape probes to query and form parameters, then requiring browser-executed proof from the PTK browser-nav harness.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Anti-clickjacking Header</title>
      <link>/docs/alerts/10020/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10020/</guid>
      <description></description>
    </item>
    <item>
      <title>Anti-CSRF Tokens Check</title>
      <link>/docs/alerts/20012/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20012/</guid>
      <description>&lt;p&gt;A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.&lt;/p&gt;</description>
    </item>
    <item>
      <title>API docs endpoint observed</title>
      <link>/docs/alerts/200012-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-3/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>api_key/key in URL</title>
      <link>/docs/alerts/200014-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200014-3/</guid>
      <description>&lt;p&gt;Detects access tokens, JWTs, and API keys present in URLs or query strings observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple app-site-association observed</title>
      <link>/docs/alerts/200013-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-4/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Application Error Disclosure</title>
      <link>/docs/alerts/90022/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90022/</guid>
      <description>&lt;p&gt;This page contains an error/warning message that may disclose sensitive information like the location of the file that produced the unhandled exception. This information can be used to launch further attacks against the web application. The alert could be a false positive if the error message is found inside a documentation page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Application Error Disclosure via WebSockets</title>
      <link>/docs/alerts/110001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110001/</guid>
      <description>&lt;p&gt;This payload contains an error/warning message that may disclose sensitive information like the location of the file that produced the unhandled exception. This information can be used to launch further attacks against the web application.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ASP.NET ViewState Disclosure</title>
      <link>/docs/alerts/10094-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10094-1/</guid>
      <description>&lt;p&gt;An ASP.NET ViewState was disclosed by the application/web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ASP.NET ViewState Integrity</title>
      <link>/docs/alerts/10094-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10094-2/</guid>
      <description>&lt;p&gt;The application does not use a Message Authentication Code (MAC) to protect the integrity of the ASP.NET ViewState, which can be tampered with by a malicious client.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Authentication Credentials Captured</title>
      <link>/docs/alerts/10105-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10105-1/</guid>
      <description>&lt;p&gt;An insecure authentication mechanism is in use. This allows an attacker on the network access to the userid and password of the authenticated user. For Basic Authentication, the attacker must merely monitor the network traffic until a Basic Authentication request is received, and then base64 decode the username and password. For Digest Authentication, the attacker has access to the username, and possibly also the password, if the hash (including a nonce) can be successfully cracked, or if a Man-In-The-Middle attack is mounted.&#xA;The attacker eavesdrops on the network until an authentication has completed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Authentication Request Identified</title>
      <link>/docs/alerts/10111/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10111/</guid>
      <description>&lt;p&gt;The given request has been identified as an authentication request. The &amp;lsquo;Other Info&amp;rsquo; field contains a set of key=value lines which identify any relevant fields. If the request is in a context which has an Authentication Method set to &amp;ldquo;Auto-Detect&amp;rdquo; then this rule will change the authentication to match the request identified.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid eval with string literals</title>
      <link>/docs/alerts/220003-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-3/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid execScript dynamic execution</title>
      <link>/docs/alerts/220003-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-2/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid Function constructor with strings</title>
      <link>/docs/alerts/220003-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-4/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid permissive regex origin checks</title>
      <link>/docs/alerts/220008-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-4/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid postMessage with wildcard targetOrigin</title>
      <link>/docs/alerts/220008-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-1/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid string-based timers</title>
      <link>/docs/alerts/220003-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-1/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Avoid weak origin substring checks</title>
      <link>/docs/alerts/220008-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-3/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>AWS Access Key ID pattern</title>
      <link>/docs/alerts/200011-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-2/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Backup File Detected</title>
      <link>/docs/alerts/100030/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100030/</guid>
      <description>&lt;p&gt;A backup or alternate version of a page or component was detected. An attacker may leverage information in such files to further attack or abuse the system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Backup File Disclosure</title>
      <link>/docs/alerts/10095/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10095/</guid>
      <description>&lt;p&gt;A backup of the file was disclosed by the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Base64 Disclosure</title>
      <link>/docs/alerts/10094-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10094-3/</guid>
      <description>&lt;p&gt;Base64 encoded data was disclosed by the application/web server. Note: in the interests of performance not all base64 strings in the response were analyzed individually, the entire response should be looked at by the analyst/security team/developer(s).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Base64 Disclosure</title>
      <link>/docs/alerts/10094/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10094/</guid>
      <description></description>
    </item>
    <item>
      <title>Base64 Disclosure in WebSocket message</title>
      <link>/docs/alerts/110002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110002/</guid>
      <description>&lt;p&gt;A Base64-encoded string has been found in the websocket incoming message. Base64-encoded data may contain sensitive information such as usernames, passwords or cookies which should be further inspected. Decoded evidence: example.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Big Redirect Detected (Potential Sensitive Information Leak)</title>
      <link>/docs/alerts/10044-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10044-1/</guid>
      <description>&lt;p&gt;The server has responded with a redirect that seems to provide a large response. This may indicate that although the server sent a redirect it also responded with body content (which may include sensitive details, PII, etc.).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Big Redirect Detected (Potential Sensitive Information Leak)</title>
      <link>/docs/alerts/10044/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10044/</guid>
      <description></description>
    </item>
    <item>
      <title>Browser-navigation DOM XSS via URL parameters</title>
      <link>/docs/alerts/200022/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022/</guid>
      <description></description>
    </item>
    <item>
      <title>Buffer Overflow</title>
      <link>/docs/alerts/30001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/30001/</guid>
      <description>&lt;p&gt;Buffer overflow errors are characterized by the overwriting of memory spaces of the background web process, which should have never been modified intentionally or unintentionally. Overwriting values of the IP (Instruction Pointer), BP (Base Pointer) and other registers causes exceptions, segmentation faults, and other process errors to occur. Usually these errors end execution of the application in an unexpected way.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bypassing 403</title>
      <link>/docs/alerts/40038/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40038/</guid>
      <description>&lt;p&gt;Bypassing 403 endpoints may be possible, the scan rule sent a payload that caused the response to be accessible (status code 200).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cache-Control public/max-age with Set-Cookie</title>
      <link>/docs/alerts/200018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200018/</guid>
      <description>&lt;p&gt;Flags potentially risky cacheability for responses that appear user-specific and missing cache partitioning indicators.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Charset Mismatch</title>
      <link>/docs/alerts/90011-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90011-4/</guid>
      <description>&lt;p&gt;This check identifies responses where the HTTP Content-Type header declares a charset different from the charset defined by the body of the HTML or XML. When there&amp;rsquo;s a charset mismatch between the HTTP header and content body Web browsers can be forced into an undesirable content-sniffing mode to determine the content&amp;rsquo;s correct character set.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Charset Mismatch</title>
      <link>/docs/alerts/90011/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90011/</guid>
      <description></description>
    </item>
    <item>
      <title>Charset Mismatch (Header Versus Meta Charset)</title>
      <link>/docs/alerts/90011-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90011-2/</guid>
      <description>&lt;p&gt;This check identifies responses where the HTTP Content-Type header declares a charset different from the charset defined by the body of the HTML or XML. When there&amp;rsquo;s a charset mismatch between the HTTP header and content body Web browsers can be forced into an undesirable content-sniffing mode to determine the content&amp;rsquo;s correct character set.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Charset Mismatch (Header Versus Meta Content-Type Charset)</title>
      <link>/docs/alerts/90011-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90011-1/</guid>
      <description>&lt;p&gt;This check identifies responses where the HTTP Content-Type header declares a charset different from the charset defined by the body of the HTML or XML. When there&amp;rsquo;s a charset mismatch between the HTTP header and content body Web browsers can be forced into an undesirable content-sniffing mode to determine the content&amp;rsquo;s correct character set.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Charset Mismatch (Meta Charset Versus Meta Content-Type Charset)</title>
      <link>/docs/alerts/90011-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90011-3/</guid>
      <description>&lt;p&gt;This check identifies responses where the HTTP Content-Type header declares a charset different from the charset defined by the body of the HTML or XML. When there&amp;rsquo;s a charset mismatch between the HTTP header and content body Web browsers can be forced into an undesirable content-sniffing mode to determine the content&amp;rsquo;s correct character set.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Clear-Site-Data present but missing executionContexts</title>
      <link>/docs/alerts/200005-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-17/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Clear-Site-Data uses wildcard *</title>
      <link>/docs/alerts/200005-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-18/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client Script Loader Poisoning</title>
      <link>/docs/alerts/220007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007/</guid>
      <description></description>
    </item>
    <item>
      <title>Client-Side Data Flow</title>
      <link>/docs/alerts/40100/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40100/</guid>
      <description>&lt;p&gt;An interesting data-flow was found in client-side JavaScript&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side HTTP exfiltration sinks</title>
      <link>/docs/alerts/210013/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013/</guid>
      <description></description>
    </item>
    <item>
      <title>Client-side navigation sinks</title>
      <link>/docs/alerts/210002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210002/</guid>
      <description></description>
    </item>
    <item>
      <title>Client-side redirect via history.pushState</title>
      <link>/docs/alerts/210015-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-4/</guid>
      <description>&lt;p&gt;Tainted URL passed to history.pushState, altering client-side navigation.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side redirect via location.assign</title>
      <link>/docs/alerts/210015-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-2/</guid>
      <description>&lt;p&gt;Tainted destination URL passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side redirect via location.href</title>
      <link>/docs/alerts/210015-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-1/</guid>
      <description>&lt;p&gt;Tainted data assigned to location.href, causing a client-side redirect.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side redirect via location.replace</title>
      <link>/docs/alerts/210015-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-3/</guid>
      <description>&lt;p&gt;Tainted destination URL passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side route change via history.replaceState</title>
      <link>/docs/alerts/210015-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015-5/</guid>
      <description>&lt;p&gt;Tainted URL passed to history.replaceState, altering client-side navigation state.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Client-side Template Injection</title>
      <link>/docs/alerts/220005/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005/</guid>
      <description></description>
    </item>
    <item>
      <title>Cloud metadata IP referenced</title>
      <link>/docs/alerts/200016-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-4/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Metadata Potentially Exposed</title>
      <link>/docs/alerts/90034/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90034/</guid>
      <description>&lt;p&gt;The Cloud Metadata Attack attempts to abuse a misconfigured NGINX server in order to access the instance metadata maintained by cloud service providers such as AWS, GCP and Azure.&#xA;All of these providers provide metadata via an internal unroutable IP address &amp;lsquo;169.254.169.254&amp;rsquo; - this can be exposed by incorrectly configured NGINX servers and accessed by using this IP address in the Host header field.&lt;/p&gt;</description>
    </item>
    <item>
      <title>COEP present but value is not &#39;require-corp&#39; or &#39;credentialless&#39;</title>
      <link>/docs/alerts/200005-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-14/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Content Cacheability</title>
      <link>/docs/alerts/10049/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10049/</guid>
      <description></description>
    </item>
    <item>
      <title>Content Security Policy (CSP) Header Not Set</title>
      <link>/docs/alerts/10038-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10038-1/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Content Security Policy (CSP) Header Not Set</title>
      <link>/docs/alerts/10038/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10038/</guid>
      <description></description>
    </item>
    <item>
      <title>Content Security Policy (CSP) Report-Only Header Found</title>
      <link>/docs/alerts/10038-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10038-3/</guid>
      <description>&lt;p&gt;The response contained a Content-Security-Policy-Report-Only header, this may indicate a work-in-progress implementation, or an oversight in promoting pre-Prod to Prod, etc.&lt;/p&gt;&#xA;&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Content Security Policy Violations Reporting Enabled</title>
      <link>/docs/alerts/100004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100004/</guid>
      <description></description>
    </item>
    <item>
      <title>Content-Type Header Empty</title>
      <link>/docs/alerts/10019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10019-2/</guid>
      <description>&lt;p&gt;The Content-Type header was either missing or empty.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Content-Type Header Missing</title>
      <link>/docs/alerts/10019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10019-1/</guid>
      <description>&lt;p&gt;The Content-Type header was either missing or empty.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Content-Type Header Missing</title>
      <link>/docs/alerts/10019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10019/</guid>
      <description></description>
    </item>
    <item>
      <title>Cookie No HttpOnly Flag</title>
      <link>/docs/alerts/10010/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10010/</guid>
      <description>&lt;p&gt;A cookie has been set without the HttpOnly flag, which means that the cookie can be accessed by JavaScript. If a malicious script can be run on this page then the cookie will be accessible and can be transmitted to another site. If this is a session cookie then session hijacking may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie Poisoning</title>
      <link>/docs/alerts/10029/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10029/</guid>
      <description>&lt;p&gt;This check looks at user-supplied input in query string parameters and POST data to identify where cookie parameters might be controlled. This is called a cookie poisoning attack, and becomes exploitable when an attacker can manipulate the cookie in various ways. In some cases this will not be exploitable, however, allowing URL parameters to set cookie values is generally considered a bug.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie Set Without HttpOnly Flag</title>
      <link>/docs/alerts/100003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100003/</guid>
      <description>&lt;p&gt;A cookie has been set without the HttpOnly flag, which means that the cookie can be accessed by JavaScript. If a malicious script can be run on this page then the cookie will be accessible and can be transmitted to another site. If this is a session cookie then session hijacking may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie Slack Detector</title>
      <link>/docs/alerts/90027/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90027/</guid>
      <description>&lt;p&gt;Repeated GET requests: drop a different cookie each time, followed by normal request with all cookies to stabilize session, compare responses against original baseline GET. This can reveal areas where cookie based authentication/attributes are not actually enforced.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie with Invalid SameSite Attribute</title>
      <link>/docs/alerts/10054-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10054-3/</guid>
      <description>&lt;p&gt;A cookie has been set with an invalid SameSite attribute value, which means that the cookie can be sent as a result of a &amp;lsquo;cross-site&amp;rsquo; request. The SameSite attribute is an effective counter measure to cross-site request forgery, cross-site script inclusion, and timing attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie with SameSite Attribute None</title>
      <link>/docs/alerts/10054-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10054-2/</guid>
      <description>&lt;p&gt;A cookie has been set with its SameSite attribute set to &amp;ldquo;none&amp;rdquo;, which means that the cookie can be sent as a result of a &amp;lsquo;cross-site&amp;rsquo; request. The SameSite attribute is an effective counter measure to cross-site request forgery, cross-site script inclusion, and timing attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie without SameSite Attribute</title>
      <link>/docs/alerts/10054-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10054-1/</guid>
      <description>&lt;p&gt;A cookie has been set without the SameSite attribute, which means that the cookie can be sent as a result of a &amp;lsquo;cross-site&amp;rsquo; request. The SameSite attribute is an effective counter measure to cross-site request forgery, cross-site script inclusion, and timing attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie without SameSite Attribute</title>
      <link>/docs/alerts/10054/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10054/</guid>
      <description></description>
    </item>
    <item>
      <title>Cookie Without Secure Flag</title>
      <link>/docs/alerts/10011/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10011/</guid>
      <description>&lt;p&gt;A cookie has been set without the secure flag, which means that the cookie can be accessed via unencrypted connections.&lt;/p&gt;</description>
    </item>
    <item>
      <title>COOP present but value is not &#39;same-origin&#39;</title>
      <link>/docs/alerts/200005-23/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-23/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>COOP set without COEP/CORP (incomplete cross-origin isolation)</title>
      <link>/docs/alerts/200005-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-13/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS allows any origin with credentials</title>
      <link>/docs/alerts/200005-19/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-19/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS allows broad headers</title>
      <link>/docs/alerts/200017-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200017-3/</guid>
      <description>&lt;p&gt;Adds passive CORS posture checks: missing Vary: Origin for dynamic ACAO, and permissive allowed headers/methods.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS allows broad methods</title>
      <link>/docs/alerts/200017-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200017-2/</guid>
      <description>&lt;p&gt;Adds passive CORS posture checks: missing Vary: Origin for dynamic ACAO, and permissive allowed headers/methods.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS Header</title>
      <link>/docs/alerts/40040-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40040-1/</guid>
      <description>&lt;p&gt;Cross-Origin Resource Sharing (CORS) is an HTTP-header based mechanism that allows a server to indicate any other origins (domain, scheme, or port) than its own from which a browser should permit loading of resources. It relaxes the Same-Origin Policy (SOP).&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS Header</title>
      <link>/docs/alerts/40040/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40040/</guid>
      <description></description>
    </item>
    <item>
      <title>CORS Misconfiguration</title>
      <link>/docs/alerts/40040-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40040-2/</guid>
      <description>&lt;p&gt;This CORS misconfiguration could allow an attacker to perform AJAX queries to the vulnerable website from a malicious page loaded by the victim&amp;rsquo;s user agent.&#xA;In order to perform authenticated AJAX queries, the server must specify the header &amp;ldquo;Access-Control-Allow-Credentials: true&amp;rdquo; and the &amp;ldquo;Access-Control-Allow-Origin&amp;rdquo; header must be set to null or the malicious page&amp;rsquo;s domain. Even if this misconfiguration doesn&amp;rsquo;t allow authenticated AJAX requests, unauthenticated sensitive content can still be accessed (e.g intranet websites).&#xA;A malicious page can belong to a malicious website but also a trusted website with flaws (e.g XSS, support of HTTP without TLS allowing code injection through MITM, etc).&lt;/p&gt;</description>
    </item>
    <item>
      <title>CORS Misconfiguration</title>
      <link>/docs/alerts/40040-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40040-3/</guid>
      <description>&lt;p&gt;This CORS misconfiguration could allow an attacker to perform AJAX queries to the vulnerable website from a malicious page loaded by the victim&amp;rsquo;s user agent.&#xA;In order to perform authenticated AJAX queries, the server must specify the header &amp;ldquo;Access-Control-Allow-Credentials: true&amp;rdquo; and the &amp;ldquo;Access-Control-Allow-Origin&amp;rdquo; header must be set to null or the malicious page&amp;rsquo;s domain. Even if this misconfiguration doesn&amp;rsquo;t allow authenticated AJAX requests, unauthenticated sensitive content can still be accessed (e.g intranet websites).&#xA;A malicious page can belong to a malicious website but also a trusted website with flaws (e.g XSS, support of HTTP without TLS allowing code injection through MITM, etc).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Credit Card Number</title>
      <link>/docs/alerts/200006-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200006-1/</guid>
      <description>&lt;p&gt;Sensitive data is anything that should not be accessible to admin access, known as sensitive data. Sensitive data may include personally identifiable information (PII), such as Social Security numbers, financial information, or login credentials. Sensitive Data Exposure occurs when an organization unknowingly exposes sensitive data or when a security incident leads to the accidental or unlawful destruction, loss, alteration, or admin disclosure of, or access to sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CRLF Injection</title>
      <link>/docs/alerts/40003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40003/</guid>
      <description>&lt;p&gt;Cookie can be set via CRLF injection. It may also be possible to set arbitrary HTTP response headers. In addition, by carefully crafting the injected response using cross-site script, cache poisoning vulnerability may also exist.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross Site Request Forgery</title>
      <link>/docs/alerts/40103/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40103/</guid>
      <description>&lt;p&gt;A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross Site Scripting (DOM Based)</title>
      <link>/docs/alerts/40026/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40026/</guid>
      <description>&lt;p&gt;Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user&amp;rsquo;s browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.&#xA;When an attacker gets a user&amp;rsquo;s browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross Site Scripting (Persistent)</title>
      <link>/docs/alerts/40014-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40014-1/</guid>
      <description>&lt;p&gt;Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user&amp;rsquo;s browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.&#xA;When an attacker gets a user&amp;rsquo;s browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross Site Scripting (Persistent)</title>
      <link>/docs/alerts/40014-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40014-3/</guid>
      <description>&lt;p&gt;Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user&amp;rsquo;s browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.&#xA;When an attacker gets a user&amp;rsquo;s browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross Site Scripting (Persistent)</title>
      <link>/docs/alerts/40014/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40014/</guid>
      <description></description>
    </item>
    <item>
      <title>Cross Site Scripting (Persistent) - Prime</title>
      <link>/docs/alerts/40016/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40016/</guid>
      <description></description>
    </item>
    <item>
      <title>Cross Site Scripting (Persistent) - Spider</title>
      <link>/docs/alerts/40017/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40017/</guid>
      <description></description>
    </item>
    <item>
      <title>Cross Site Scripting (Reflected)</title>
      <link>/docs/alerts/40012/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40012/</guid>
      <description>&lt;p&gt;Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user&amp;rsquo;s browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.&#xA;When an attacker gets a user&amp;rsquo;s browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross Site Scripting Weakness (Persistent in JSON Response)</title>
      <link>/docs/alerts/40014-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40014-2/</guid>
      <description>&lt;p&gt;A XSS attack was found in a JSON response, this might leave content consumers vulnerable to attack if they don&amp;rsquo;t appropriately handle the data (response).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Domain JavaScript Source File Inclusion</title>
      <link>/docs/alerts/10017/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10017/</guid>
      <description>&lt;p&gt;The page includes one or more script files from a third-party domain.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Domain Misconfiguration</title>
      <link>/docs/alerts/10098/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10098/</guid>
      <description>&lt;p&gt;Web browser data loading may be possible, due to a Cross Origin Resource Sharing (CORS) misconfiguration on the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Domain Misconfiguration</title>
      <link>/docs/alerts/20016/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20016/</guid>
      <description></description>
    </item>
    <item>
      <title>Cross-Domain Misconfiguration - Adobe - Read</title>
      <link>/docs/alerts/20016-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20016-1/</guid>
      <description>&lt;p&gt;Flash/Silverlight based cross-site request forgery may be possible, due to a misconfiguration on the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Domain Misconfiguration - Adobe - Send</title>
      <link>/docs/alerts/20016-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20016-2/</guid>
      <description>&lt;p&gt;Flash/Silverlight based cross-site request forgery may be possible, due to a misconfiguration on the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Domain Misconfiguration - Silverlight</title>
      <link>/docs/alerts/20016-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20016-3/</guid>
      <description>&lt;p&gt;Silverlight based cross-site request forgery may be possible, due to a misconfiguration on the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Origin-Embedder-Policy Header Missing or Invalid</title>
      <link>/docs/alerts/90004-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90004-2/</guid>
      <description>&lt;p&gt;Cross-Origin-Embedder-Policy header is a response header that prevents a document from loading any cross-origin resources that don&amp;rsquo;t explicitly grant the document permission (using CORP or CORS).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Origin-Opener-Policy Header Missing or Invalid</title>
      <link>/docs/alerts/90004-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90004-3/</guid>
      <description>&lt;p&gt;Cross-Origin-Opener-Policy header is a response header that allows a site to control if others included documents share the same browsing context. Sharing the same browsing context with untrusted documents might lead to data leak.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Origin-Resource-Policy Header Missing or Invalid</title>
      <link>/docs/alerts/90004-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90004-1/</guid>
      <description>&lt;p&gt;Cross-Origin-Resource-Policy header is an opt-in header designed to counter side-channels attacks like Spectre. Resource should be specifically set as shareable amongst different origins.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-site Scripting</title>
      <link>/docs/alerts/40101/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40101/</guid>
      <description>&lt;p&gt;Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user&amp;rsquo;s browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.&#xA;When an attacker gets a user&amp;rsquo;s browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-site Scripting</title>
      <link>/docs/alerts/40102/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40102/</guid>
      <description>&lt;p&gt;Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user&amp;rsquo;s browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.&#xA;When an attacker gets a user&amp;rsquo;s browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Site WebSocket Hijacking</title>
      <link>/docs/alerts/100025/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100025/</guid>
      <description>&lt;p&gt;Server accepted WebSocket connection through HTTP Upgrade request with modified Origin header.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP</title>
      <link>/docs/alerts/10055/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055/</guid>
      <description></description>
    </item>
    <item>
      <title>CSP &#39;frame-ancestors&#39; missing or overly broad</title>
      <link>/docs/alerts/200005-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-3/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP allows inline/eval or wildcards in script/style</title>
      <link>/docs/alerts/200005-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-2/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP Report-Only present without enforcing CSP</title>
      <link>/docs/alerts/200005-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-4/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: Failure to Define Directive with No Fallback</title>
      <link>/docs/alerts/10055-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-13/</guid>
      <description>&lt;p&gt;The Content Security Policy fails to define one of the directives that has no fallback. Missing/excluding them is the same as allowing anything.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: Header &amp; Meta</title>
      <link>/docs/alerts/10055-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-12/</guid>
      <description>&lt;p&gt;The message contained both CSP specified via header and via Meta tag. It was not possible to union these policies in order to perform an analysis. Therefore, they have been evaluated individually.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: Malformed Policy (Non-ASCII)</title>
      <link>/docs/alerts/10055-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-9/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: Meta Policy Invalid Directive</title>
      <link>/docs/alerts/10055-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-11/</guid>
      <description>&lt;p&gt;The policy specified via meta element contains either or both the sandbox or frame-ancestors directive, which are not permitted inside meta CSP definitions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: Notices</title>
      <link>/docs/alerts/10055-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-3/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: script-src unsafe-eval</title>
      <link>/docs/alerts/10055-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-10/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: script-src unsafe-hashes</title>
      <link>/docs/alerts/10055-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-7/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: script-src unsafe-inline</title>
      <link>/docs/alerts/10055-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-5/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: style-src unsafe-hashes</title>
      <link>/docs/alerts/10055-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-8/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: style-src unsafe-inline</title>
      <link>/docs/alerts/10055-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-6/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: Wildcard Directive</title>
      <link>/docs/alerts/10055-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-4/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: X-Content-Security-Policy</title>
      <link>/docs/alerts/10055-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-1/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSP: X-WebKit-CSP</title>
      <link>/docs/alerts/10055-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10055-2/</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dangerous form target URL schemes</title>
      <link>/docs/alerts/210006/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006/</guid>
      <description></description>
    </item>
    <item>
      <title>Dangerous JS Functions</title>
      <link>/docs/alerts/10110/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10110/</guid>
      <description>&lt;p&gt;A dangerous JS function seems to be in use that would leave the site vulnerable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dangerous URL scheme execution sinks</title>
      <link>/docs/alerts/210003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003/</guid>
      <description></description>
    </item>
    <item>
      <title>data: URL assigned to form action</title>
      <link>/docs/alerts/210006-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-3/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to formAction</title>
      <link>/docs/alerts/210006-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-4/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to formAction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to href</title>
      <link>/docs/alerts/210003-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-5/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to iframe.src</title>
      <link>/docs/alerts/210003-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-15/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to iframe.src.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to script.src</title>
      <link>/docs/alerts/210003-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-4/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to script.src and treated as executable content.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL assigned to src</title>
      <link>/docs/alerts/210003-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-7/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to a generic src attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL navigated via location.assign</title>
      <link>/docs/alerts/210003-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-10/</guid>
      <description>&lt;p&gt;Tainted data: URL passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL navigated via location.href</title>
      <link>/docs/alerts/210003-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-8/</guid>
      <description>&lt;p&gt;Tainted data: URL assigned to location.href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL navigated via location.replace</title>
      <link>/docs/alerts/210003-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-12/</guid>
      <description>&lt;p&gt;Tainted data: URL passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>data: URL opened via window.open</title>
      <link>/docs/alerts/210003-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-14/</guid>
      <description>&lt;p&gt;Tainted data: URL passed to window.open.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Debug/diagnostic path observed</title>
      <link>/docs/alerts/200019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-2/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deprecated Feature Policy Header Set</title>
      <link>/docs/alerts/10063-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10063-2/</guid>
      <description>&lt;p&gt;The header has now been renamed to Permissions-Policy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deprecated Feature-Policy or unknown/overly-permissive Permissions-Policy</title>
      <link>/docs/alerts/200005-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-15/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Directory Browsing</title>
      <link>/docs/alerts/0/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/0/</guid>
      <description>&lt;p&gt;It is possible to view the directory listing. Directory listing may reveal hidden scripts, include files, backup source files, etc. which can be accessed to read sensitive information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Directory Browsing</title>
      <link>/docs/alerts/10033/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10033/</guid>
      <description>&lt;p&gt;It is possible to view a listing of the directory contents. Directory listings may reveal hidden scripts, include files, backup source files, etc., which can be accessed to reveal sensitive information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow direct document.cookie assignment (incl. bracket access)</title>
      <link>/docs/alerts/220001-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220001-1/</guid>
      <description>&lt;p&gt;Detects cases where attacker-controlled DOM data is written into cookies (document.cookie or common wrapper functions). Can indicate session fixation, logic control, or preparation for exploit-chains.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow direct navigation primitives</title>
      <link>/docs/alerts/220002-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220002-1/</guid>
      <description>&lt;p&gt;Detects client-side code that can redirect users to attacker-controlled URLs (open redirects). Includes assignment/calls that control window/location/navigation, attr-based redirects, form actions and jQuery variants.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow document.write()/writeln()</title>
      <link>/docs/alerts/220000-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-3/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow innerHTML/outerHTML assignments</title>
      <link>/docs/alerts/220000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-1/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disallow insertAdjacentHTML()</title>
      <link>/docs/alerts/220000-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-7/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM Data Manipulation</title>
      <link>/docs/alerts/220010/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220010/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM link and attribute navigation sinks</title>
      <link>/docs/alerts/210014/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM parser and unsafe HTML sinks</title>
      <link>/docs/alerts/210016/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM URL-based navigation sinks</title>
      <link>/docs/alerts/210015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210015/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM XSS from secondary client-side sources</title>
      <link>/docs/alerts/210017/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM XSS sinks</title>
      <link>/docs/alerts/210000/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM XSS via document.write</title>
      <link>/docs/alerts/210000-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-5/</guid>
      <description>&lt;p&gt;Tainted data passed to document.write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via document.write (secondary sources)</title>
      <link>/docs/alerts/210017-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-4/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached document.write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via DOM mutation (secondary sources)</title>
      <link>/docs/alerts/210017-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-6/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached mutation sinks.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via DOM mutations</title>
      <link>/docs/alerts/210000-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-6/</guid>
      <description>&lt;p&gt;Tainted data inserted into the DOM via DOM mutation APIs.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via DOMParser.parseFromString</title>
      <link>/docs/alerts/210016-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-1/</guid>
      <description>&lt;p&gt;Tainted HTML parsed through DOMParser.parseFromString with an HTML-like MIME type.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Element.innerHTML</title>
      <link>/docs/alerts/210000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-2/</guid>
      <description>&lt;p&gt;Tainted data assigned to innerHTML (possible DOM XSS).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Element.outerHTML</title>
      <link>/docs/alerts/210000-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-3/</guid>
      <description>&lt;p&gt;Tainted data assigned to outerHTML (possible DOM XSS).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Element.setHTMLUnsafe</title>
      <link>/docs/alerts/210016-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-3/</guid>
      <description>&lt;p&gt;Tainted HTML passed to Element.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via iframe.srcdoc (secondary sources)</title>
      <link>/docs/alerts/210017-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-7/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached iframe.srcdoc.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via inline event handler</title>
      <link>/docs/alerts/210000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-1/</guid>
      <description>&lt;p&gt;Tainted data flowed into an inline event handler.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via inline handlers (secondary sources)</title>
      <link>/docs/alerts/210017-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-5/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached inline event handlers.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via innerHTML (Angular)</title>
      <link>/docs/alerts/220000-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-9/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via innerHTML (secondary sources)</title>
      <link>/docs/alerts/210017-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-1/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached innerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via insertAdjacentHTML</title>
      <link>/docs/alerts/210000-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210000-4/</guid>
      <description>&lt;p&gt;Tainted HTML passed into insertAdjacentHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via insertAdjacentHTML (secondary sources)</title>
      <link>/docs/alerts/210017-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-3/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached insertAdjacentHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via outerHTML (secondary sources)</title>
      <link>/docs/alerts/210017-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210017-2/</guid>
      <description>&lt;p&gt;Persisted/reflected client-side values reached outerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param attribute breakout</title>
      <link>/docs/alerts/200022-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-2/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param attribute-name event injection</title>
      <link>/docs/alerts/200022-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-11/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param double-quoted attribute event breakout</title>
      <link>/docs/alerts/200022-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-12/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param double-quoted resource onerror breakout</title>
      <link>/docs/alerts/200022-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-13/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param event-handler value</title>
      <link>/docs/alerts/200022-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-10/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param HTML image onerror</title>
      <link>/docs/alerts/200022-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-1/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param javascript: URL</title>
      <link>/docs/alerts/200022-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-17/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS block-comment breakout</title>
      <link>/docs/alerts/200022-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-8/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS double-quote breakout</title>
      <link>/docs/alerts/200022-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-3/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS expression execution</title>
      <link>/docs/alerts/200022-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-6/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS regex breakout</title>
      <link>/docs/alerts/200022-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-7/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS single-quote breakout</title>
      <link>/docs/alerts/200022-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-4/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param JS template literal breakout</title>
      <link>/docs/alerts/200022-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-5/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param script-tag breakout</title>
      <link>/docs/alerts/200022-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-9/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param single-quoted attribute event breakout</title>
      <link>/docs/alerts/200022-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-14/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param style-block breakout</title>
      <link>/docs/alerts/200022-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-18/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param SVG tag-name event injection</title>
      <link>/docs/alerts/200022-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-16/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via query param unquoted attribute event injection</title>
      <link>/docs/alerts/200022-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200022-15/</guid>
      <description>&lt;p&gt;Tests top-level GET query parameters for browser-executed XSS by opening a real browser attack tab and requiring an execution marker after load or safe synthetic interaction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via Range.createContextualFragment</title>
      <link>/docs/alerts/210016-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-2/</guid>
      <description>&lt;p&gt;Tainted HTML passed to Range.createContextualFragment.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM XSS via ShadowRoot.setHTMLUnsafe</title>
      <link>/docs/alerts/210016-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210016-4/</guid>
      <description>&lt;p&gt;Tainted HTML passed to ShadowRoot.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based Cookie Manipulation</title>
      <link>/docs/alerts/220001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220001/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM-based Cookie Manipulation (taint flow)</title>
      <link>/docs/alerts/220001-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220001-2/</guid>
      <description>&lt;p&gt;Detects cases where attacker-controlled DOM data is written into cookies (document.cookie or common wrapper functions). Can indicate session fixation, logic control, or preparation for exploit-chains.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based JavaScript Injection</title>
      <link>/docs/alerts/220003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM-based JavaScript Injection (taint flow)</title>
      <link>/docs/alerts/220003-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220003-5/</guid>
      <description>&lt;p&gt;Detects dynamic execution of attacker-controlled strings in JavaScript sinks such as eval(), Function(), string-based timers, execScript, or script.text assignments. Exploiting these flows lets attackers execute arbitrary JS without relying on HTML injection.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based Link Manipulation</title>
      <link>/docs/alerts/220009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220009/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM-based Link Manipulation (taint flow)</title>
      <link>/docs/alerts/220009-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220009-2/</guid>
      <description>&lt;p&gt;Detects DOM code that rewrites link destinations (href attributes) with attacker-controlled data. Manipulated links can mislead users into visiting malicious targets even if navigation is not forced automatically.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based Open Redirection (taint flow)</title>
      <link>/docs/alerts/220002-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220002-3/</guid>
      <description>&lt;p&gt;Detects client-side code that can redirect users to attacker-controlled URLs (open redirects). Includes assignment/calls that control window/location/navigation, attr-based redirects, form actions and jQuery variants.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>DOM-based XSS</title>
      <link>/docs/alerts/220000/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000/</guid>
      <description></description>
    </item>
    <item>
      <title>DOM-based XSS (taint flow)</title>
      <link>/docs/alerts/220000-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-8/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic ACAO without Vary: Origin</title>
      <link>/docs/alerts/200017-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200017-1/</guid>
      <description>&lt;p&gt;Adds passive CORS posture checks: missing Vary: Origin for dynamic ACAO, and permissive allowed headers/methods.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic AngularJS $compile/$interpolate template</title>
      <link>/docs/alerts/220004-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-4/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic AngularJS $parse expression</title>
      <link>/docs/alerts/220004-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-3/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic code execution via eval</title>
      <link>/docs/alerts/210001-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210001-1/</guid>
      <description>&lt;p&gt;Tainted string executed via eval().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic code execution via Function constructor</title>
      <link>/docs/alerts/210001-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210001-2/</guid>
      <description>&lt;p&gt;Tainted string executed via Function constructor.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic code execution via Function.apply</title>
      <link>/docs/alerts/210001-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210001-3/</guid>
      <description>&lt;p&gt;Tainted string executed via Function.apply.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic JS execution</title>
      <link>/docs/alerts/210001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210001/</guid>
      <description></description>
    </item>
    <item>
      <title>Dynamic template compilation</title>
      <link>/docs/alerts/220005-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-1/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>ELMAH Information Leak</title>
      <link>/docs/alerts/40028/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40028/</guid>
      <description>&lt;p&gt;The Error Logging Modules and Handlers (ELMAH [elmah.axd]) HTTP Module was found to be available. This module can leak a significant amount of valuable information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Email address found in WebSocket message</title>
      <link>/docs/alerts/110004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110004/</guid>
      <description>&lt;p&gt;An email address was found in a WebSocket Message.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Emails Found in the Viewstate</title>
      <link>/docs/alerts/10032-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-2/</guid>
      <description>&lt;p&gt;Email addresses were found being serialized in the viewstate field.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Environment hints (dev/staging/test) in response</title>
      <link>/docs/alerts/200016-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-3/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Environment/config file observed</title>
      <link>/docs/alerts/200019-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-7/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>eval() from storage/referrer taint</title>
      <link>/docs/alerts/210018-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-1/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached eval().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via fetch headers</title>
      <link>/docs/alerts/210013-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-2/</guid>
      <description>&lt;p&gt;Tainted data sent in fetch() headers (e.g. Authorization, custom tokens).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via fetch URL</title>
      <link>/docs/alerts/210013-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-1/</guid>
      <description>&lt;p&gt;Tainted data used in fetch() URL, potentially exfiltrating sensitive information.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via image.src beacon</title>
      <link>/docs/alerts/210013-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-7/</guid>
      <description>&lt;p&gt;Tainted data embedded into image src URL for beacon-style exfiltration.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via navigator.sendBeacon</title>
      <link>/docs/alerts/210013-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-6/</guid>
      <description>&lt;p&gt;Tainted data sent via navigator.sendBeacon().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest body</title>
      <link>/docs/alerts/210013-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-4/</guid>
      <description>&lt;p&gt;Tainted data sent in XMLHttpRequest.send() body.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest headers</title>
      <link>/docs/alerts/210013-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-5/</guid>
      <description>&lt;p&gt;Tainted data sent in XMLHttpRequest.setRequestHeader() values.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exfiltration via XMLHttpRequest URL</title>
      <link>/docs/alerts/210013-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210013-3/</guid>
      <description>&lt;p&gt;Tainted data used in XMLHttpRequest.open() URL.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Expect-CT is deprecated</title>
      <link>/docs/alerts/200005-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-12/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exponential Entity Expansion (Billion Laughs Attack)</title>
      <link>/docs/alerts/40044/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40044/</guid>
      <description>&lt;p&gt;An exponential entity expansion, or &amp;ldquo;billion laughs&amp;rdquo; attack is a type of denial-of-service (DoS) attack. It is aimed at parsers of markup languages like XML or YAML that allow macro expansions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposed Secrets in Swagger/OpenAPI Path</title>
      <link>/docs/alerts/100043-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100043-2/</guid>
      <description>&lt;p&gt;Swagger UI endpoint exposes sensitive secrets such as client secrets, API keys, or OAuth tokens. These secrets may be accessible in the HTML source and should not be exposed publicly, as this can lead to compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposed Session ID</title>
      <link>/docs/alerts/40013-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40013-5/</guid>
      <description>&lt;p&gt;A session id is exposed in the URL. By sharing such a website URL (containing the session id), a naive user may be inadvertently granting access to their data, compromising its confidentiality, integrity, and availability. URLs containing the session identifier also appear in web browser bookmarks, web server log files, and proxy server log files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposure of Git repository</title>
      <link>/docs/alerts/200004-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200004-1/</guid>
      <description>&lt;p&gt;Version control repositories such as CVS or git store version-specific metadata and other details within subdirectories. If these subdirectories are stored on a web server or added to an archive, then these could be used by an attacker. This information may include usernames, filenames, path root, IP addresses, and detailed &amp;lsquo;diff&amp;rsquo; data about how files have been changed - which could reveal source code snippets that were never intended to be made public..&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposure of Mercurial repository</title>
      <link>/docs/alerts/200004-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200004-3/</guid>
      <description>&lt;p&gt;Version control repositories such as CVS or git store version-specific metadata and other details within subdirectories. If these subdirectories are stored on a web server or added to an archive, then these could be used by an attacker. This information may include usernames, filenames, path root, IP addresses, and detailed &amp;lsquo;diff&amp;rsquo; data about how files have been changed - which could reveal source code snippets that were never intended to be made public..&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposure of SVN repository</title>
      <link>/docs/alerts/200004-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200004-2/</guid>
      <description>&lt;p&gt;Version control repositories such as CVS or git store version-specific metadata and other details within subdirectories. If these subdirectories are stored on a web server or added to an archive, then these could be used by an attacker. This information may include usernames, filenames, path root, IP addresses, and detailed &amp;lsquo;diff&amp;rsquo; data about how files have been changed - which could reveal source code snippets that were never intended to be made public..&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exposure of Version-Control Repository</title>
      <link>/docs/alerts/200004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200004/</guid>
      <description></description>
    </item>
    <item>
      <title>Expression Language Injection</title>
      <link>/docs/alerts/90025/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90025/</guid>
      <description>&lt;p&gt;The software constructs all or part of an expression language (EL) statement in a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed. In certain versions of Spring 3.0.5 and earlier, there was a vulnerability (CVE-2011-2730) in which Expression Language tags would be evaluated twice, which effectively exposed any application to EL injection. However, even for later versions, this weakness is still possible depending on configuration.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ExtensionGraphQl</title>
      <link>/docs/alerts/50007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/50007/</guid>
      <description></description>
    </item>
    <item>
      <title>External Redirect</title>
      <link>/docs/alerts/20019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20019-1/</guid>
      <description>&lt;p&gt;URL redirectors represent common functionality employed by web sites to forward an incoming request to an alternate resource. This can be done for a variety of reasons and is often done to allow resources to be moved within the directory structure and to avoid breaking functionality for users that request the resource at its previous location. URL redirectors may also be used to implement load balancing, leveraging abbreviated URLs or recording outgoing links. It is this last implementation which is often used in phishing attacks as described in the example below. URL redirectors do not necessarily represent a direct security vulnerability but can be abused by attackers trying to social engineer victims into believing that they are navigating to a site other than the true destination.&lt;/p&gt;</description>
    </item>
    <item>
      <title>External Redirect</title>
      <link>/docs/alerts/20019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20019-2/</guid>
      <description>&lt;p&gt;URL redirectors represent common functionality employed by web sites to forward an incoming request to an alternate resource. This can be done for a variety of reasons and is often done to allow resources to be moved within the directory structure and to avoid breaking functionality for users that request the resource at its previous location. URL redirectors may also be used to implement load balancing, leveraging abbreviated URLs or recording outgoing links. It is this last implementation which is often used in phishing attacks as described in the example below. URL redirectors do not necessarily represent a direct security vulnerability but can be abused by attackers trying to social engineer victims into believing that they are navigating to a site other than the true destination.&lt;/p&gt;</description>
    </item>
    <item>
      <title>External Redirect</title>
      <link>/docs/alerts/20019-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20019-3/</guid>
      <description>&lt;p&gt;URL redirectors represent common functionality employed by web sites to forward an incoming request to an alternate resource. This can be done for a variety of reasons and is often done to allow resources to be moved within the directory structure and to avoid breaking functionality for users that request the resource at its previous location. URL redirectors may also be used to implement load balancing, leveraging abbreviated URLs or recording outgoing links. It is this last implementation which is often used in phishing attacks as described in the example below. URL redirectors do not necessarily represent a direct security vulnerability but can be abused by attackers trying to social engineer victims into believing that they are navigating to a site other than the true destination.&lt;/p&gt;</description>
    </item>
    <item>
      <title>External Redirect</title>
      <link>/docs/alerts/20019-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20019-4/</guid>
      <description>&lt;p&gt;URL redirectors represent common functionality employed by web sites to forward an incoming request to an alternate resource. This can be done for a variety of reasons and is often done to allow resources to be moved within the directory structure and to avoid breaking functionality for users that request the resource at its previous location. URL redirectors may also be used to implement load balancing, leveraging abbreviated URLs or recording outgoing links. It is this last implementation which is often used in phishing attacks as described in the example below. URL redirectors do not necessarily represent a direct security vulnerability but can be abused by attackers trying to social engineer victims into believing that they are navigating to a site other than the true destination.&lt;/p&gt;</description>
    </item>
    <item>
      <title>External Redirect</title>
      <link>/docs/alerts/20019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20019/</guid>
      <description></description>
    </item>
    <item>
      <title>Fetch Metadata Request Headers</title>
      <link>/docs/alerts/90005/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005/</guid>
      <description></description>
    </item>
    <item>
      <title>File Content Disclosure (CVE-2019-5418)</title>
      <link>/docs/alerts/100029/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100029/</guid>
      <description>&lt;p&gt;The application seems to be subject to CVE-2019-5418. By sending a specially crafted request it was possible to have the target return data from the server file system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>File Upload</title>
      <link>/docs/alerts/40041/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40041/</guid>
      <description>&lt;p&gt;File Upload scan rule is used to scan the vulnerabilities in the File Upload functionality of web applications.&lt;/p&gt;</description>
    </item>
    <item>
      <title>File/path candidate parameter</title>
      <link>/docs/alerts/200015-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-3/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Firebase config exposed</title>
      <link>/docs/alerts/200011-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-6/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Form action manipulated by tainted route or body input</title>
      <link>/docs/alerts/210005-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210005-1/</guid>
      <description>&lt;p&gt;Tainted route, body, or messaging value changed form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Form action manipulated from tainted source</title>
      <link>/docs/alerts/210019-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-7/</guid>
      <description>&lt;p&gt;Tainted value assigned to form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Form submission target hijack</title>
      <link>/docs/alerts/210005/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210005/</guid>
      <description></description>
    </item>
    <item>
      <title>formAction manipulated by tainted route or body input</title>
      <link>/docs/alerts/210005-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210005-2/</guid>
      <description>&lt;p&gt;Tainted route, body, or messaging value changed formAction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Format String Error</title>
      <link>/docs/alerts/30002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/30002/</guid>
      <description>&lt;p&gt;A Format String error occurs when the submitted data of an input string is evaluated as a command by the application.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Full Path Disclosure</title>
      <link>/docs/alerts/110009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110009/</guid>
      <description>&lt;p&gt;The full path of files which might be sensitive has been exposed to the client.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Function.apply() from storage/referrer taint</title>
      <link>/docs/alerts/210018-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-3/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached Function.apply().&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Function() from storage/referrer taint</title>
      <link>/docs/alerts/210018-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-2/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached Function constructor.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Generic Padding Oracle</title>
      <link>/docs/alerts/90024/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90024/</guid>
      <description>&lt;p&gt;By manipulating the padding on an encrypted string, an attacker is able to generate an error message that indicates a likely &amp;lsquo;padding oracle&amp;rsquo; vulnerability. Such a vulnerability can affect any application or framework that uses encryption improperly, such as some versions of ASP.net, Java Server Faces, and Mono. An attacker may exploit this issue to decrypt data and recover encryption keys, potentially viewing and modifying confidential data. This rule should detect the MS10-070 padding oracle vulnerability in ASP.net if CustomErrors are enabled for that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GET for POST</title>
      <link>/docs/alerts/10058/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10058/</guid>
      <description>&lt;p&gt;A request that was originally observed as a POST was also accepted as a GET. This issue does not represent a security weakness unto itself, however, it may facilitate simplification of other attacks. For example if the original POST is subject to Cross-Site Scripting (XSS), then this finding may indicate that a simplified (GET based) XSS may also be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitHub token pattern</title>
      <link>/docs/alerts/200011-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-4/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Google API key pattern</title>
      <link>/docs/alerts/200011-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-9/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphiQL / GraphQL Playground detected</title>
      <link>/docs/alerts/200012-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-5/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL Circular Type Reference</title>
      <link>/docs/alerts/50007-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/50007-3/</guid>
      <description>&lt;p&gt;A circular reference was detected in the GraphQL schema, where object types reference each other in a cycle. This can be exploited by attackers to craft deeply recursive queries, potentially leading to Denial of Service (DoS) conditions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL endpoint observed</title>
      <link>/docs/alerts/200012-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-4/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL Endpoint Supports Introspection</title>
      <link>/docs/alerts/50007-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/50007-1/</guid>
      <description>&lt;p&gt;The GraphQL endpoint has Introspection enabled. Introspection allows clients to query the schema and retrieve detailed information about the fields, types, inputs, etc. supported by the GraphQL endpoint. This may be valuable to an attacker, as it could enable them to craft more targeted queries.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL path observed</title>
      <link>/docs/alerts/200019-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-5/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>GraphQL Server Implementation Identified</title>
      <link>/docs/alerts/50007-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/50007-2/</guid>
      <description>&lt;p&gt;The server is using &amp;ldquo;Example GraphQL Engine&amp;rdquo;, which is a GraphQL implementation for &amp;ldquo;Example Technology 1&amp;rdquo; and &amp;ldquo;Example Technology 2&amp;rdquo;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure</title>
      <link>/docs/alerts/10097/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097/</guid>
      <description></description>
    </item>
    <item>
      <title>Hash Disclosure - BCrypt</title>
      <link>/docs/alerts/10097-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-7/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - BCrypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - Kerberos AFS DES</title>
      <link>/docs/alerts/10097-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-2/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - Kerberos AFS DES&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - LanMan</title>
      <link>/docs/alerts/10097-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-15/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - LanMan&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - LanMan / DES</title>
      <link>/docs/alerts/10097-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-1/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - LanMan / DES&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - MD4 / MD5</title>
      <link>/docs/alerts/10097-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-16/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - MD4 / MD5&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - MD5 Crypt</title>
      <link>/docs/alerts/10097-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-4/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - MD5 Crypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - NTLM</title>
      <link>/docs/alerts/10097-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-8/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - NTLM&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - OpenBSD Blowfish</title>
      <link>/docs/alerts/10097-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-3/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - OpenBSD Blowfish&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - Salted SHA-1</title>
      <link>/docs/alerts/10097-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-9/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - Salted SHA-1&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-1</title>
      <link>/docs/alerts/10097-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-14/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-1&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-224</title>
      <link>/docs/alerts/10097-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-13/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-224&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-256</title>
      <link>/docs/alerts/10097-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-12/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-256&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-256 Crypt</title>
      <link>/docs/alerts/10097-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-5/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-256 Crypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-384</title>
      <link>/docs/alerts/10097-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-11/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-384&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-512</title>
      <link>/docs/alerts/10097-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-10/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-512&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hash Disclosure - SHA-512 Crypt</title>
      <link>/docs/alerts/10097-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10097-6/</guid>
      <description>&lt;p&gt;A hash was disclosed by the web server. - SHA-512 Crypt&lt;/p&gt;</description>
    </item>
    <item>
      <title>Heartbleed OpenSSL Vulnerability</title>
      <link>/docs/alerts/20015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20015/</guid>
      <description>&lt;p&gt;The TLS implementation in OpenSSL 1.0.1 before 1.0.1g does not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, potentially disclosing sensitive information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Heartbleed OpenSSL Vulnerability (Indicative)</title>
      <link>/docs/alerts/10034/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10034/</guid>
      <description>&lt;p&gt;The TLS and DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, potentially disclosing sensitive information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hidden File Found</title>
      <link>/docs/alerts/40035/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40035/</guid>
      <description>&lt;p&gt;A sensitive file was identified as accessible or available. This may leak administrative, configuration, or credential information which can be leveraged by a malicious individual to further attack the system or conduct social engineering efforts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HSTS max-age too low or missing includeSubDomains</title>
      <link>/docs/alerts/200005-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-7/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTML references .map files</title>
      <link>/docs/alerts/200009-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-2/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTP Only Site</title>
      <link>/docs/alerts/10106/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10106/</guid>
      <description>&lt;p&gt;The site is only served under HTTP and not HTTPS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTP Parameter Override</title>
      <link>/docs/alerts/10026/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10026/</guid>
      <description>&lt;p&gt;Unspecified form action: HTTP parameter override attack potentially possible. This is a known problem with Java Servlets but other platforms may also be vulnerable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTP Parameter Pollution</title>
      <link>/docs/alerts/20014/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20014/</guid>
      <description>&lt;p&gt;HTTP Parameter Pollution (HPP) attacks consist of injecting encoded query string delimiters into other existing parameters. If a web application does not properly sanitize the user input, a malicious user can compromise the logic of the application to perform either client-side or server-side attacks. One consequence of HPP attacks is that the attacker can potentially override existing hard-coded HTTP parameters to modify the behavior of an application, bypass input validation checkpoints, and access and possibly exploit variables that may be out of direct reach.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTP Server Response Header</title>
      <link>/docs/alerts/10036/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10036/</guid>
      <description></description>
    </item>
    <item>
      <title>HTTP to HTTPS Insecure Transition in Form Post</title>
      <link>/docs/alerts/10041/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10041/</guid>
      <description>&lt;p&gt;This check looks for insecure HTTP pages that host HTTPS forms. The issue is that an insecure HTTP page can easily be hijacked through MITM and the secure HTTPS form can be replaced or spoofed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Httpoxy - Proxy Header Misuse</title>
      <link>/docs/alerts/10107/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10107/</guid>
      <description>&lt;p&gt;The server initiated a proxied request via the proxy specified in the HTTP Proxy header of the request.Httpoxy typically affects code running in CGI or CGI like environments.&#xA;This may allow attackers to:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Proxy the outgoing HTTP requests made by the web application&lt;/li&gt;&#xA;&lt;li&gt;Direct the server to open outgoing connections to an address and port of their choosing or&lt;/li&gt;&#xA;&lt;li&gt;Tie up server resources by forcing the vulnerable software to use a malicious proxy.&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>HTTPS Configuration</title>
      <link>/docs/alerts/10205-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10205-1/</guid>
      <description>&lt;p&gt;Performs HTTPS configuration analysis including certificate details and supported cipher suites.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTPS Configuration</title>
      <link>/docs/alerts/10205/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10205/</guid>
      <description></description>
    </item>
    <item>
      <title>HTTPS Content Available via HTTP</title>
      <link>/docs/alerts/10047/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10047/</guid>
      <description>&lt;p&gt;Content which was initially accessed via HTTPS (i.e.: using SSL/TLS encryption) is also accessible via HTTP (without encryption).&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTPS Security Configuration Issues</title>
      <link>/docs/alerts/10205-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10205-2/</guid>
      <description>&lt;p&gt;The HTTPS configuration has one or more security issues identified by the TLS risk assessment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HTTPS to HTTP Insecure Transition in Form Post</title>
      <link>/docs/alerts/10042/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10042/</guid>
      <description>&lt;p&gt;This check identifies secure HTTPS pages that host insecure HTTP forms. The issue is that a secure page is transitioning to an insecure page when data is uploaded through a form. The user may think they&amp;rsquo;re submitting data to a secure page when in fact they are not.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HUNT Methodology</title>
      <link>/docs/alerts/100015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100015/</guid>
      <description>&lt;p&gt;Find possible vulnerable entry points using HUNT Methodology (&lt;a href=&#34;https://github.com/bugcrowd/HUNT)&#34;&gt;https://github.com/bugcrowd/HUNT)&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IDOR candidate parameter</title>
      <link>/docs/alerts/200015-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-4/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>IFrame content injection via srcdoc</title>
      <link>/docs/alerts/210012-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210012-2/</guid>
      <description>&lt;p&gt;Tainted HTML assigned to iframe.srcdoc, enabling DOM-based XSS inside the frame.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>IFrame navigation and content sinks</title>
      <link>/docs/alerts/210012/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210012/</guid>
      <description></description>
    </item>
    <item>
      <title>IFrame navigation via src</title>
      <link>/docs/alerts/210012-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210012-1/</guid>
      <description>&lt;p&gt;Tainted URL assigned to iframe.src, causing navigation to untrusted content.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Image Exposes Location or Privacy Data</title>
      <link>/docs/alerts/10103/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10103/</guid>
      <description>&lt;p&gt;The image was found to contain embedded location information, such as GPS coordinates, or another privacy exposure, such as camera serial number.  Depending on the context of the image in the website, this information may expose private details of the users of a site.  For example, a site that allows users to upload profile pictures taken in the home may expose the home&amp;rsquo;s address.&lt;/p&gt;</description>
    </item>
    <item>
      <title>In Page Banner Information Leak</title>
      <link>/docs/alerts/10009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10009/</guid>
      <description>&lt;p&gt;The server returned a version banner string in the response content. Such information leaks may allow attackers to further target specific issues impacting the product and version in use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Amazon S3 Bucket URL</title>
      <link>/docs/alerts/100036/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100036/</guid>
      <description>&lt;p&gt;An Amazon S3 bucket URL was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Base64-encoded String</title>
      <link>/docs/alerts/100007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100007/</guid>
      <description>&lt;p&gt;A Base64-encoded string has been found in the HTTP response body. Base64-encoded data may contain sensitive information such as usernames, passwords or cookies which should be further inspected.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Credit Card Number</title>
      <link>/docs/alerts/100008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100008/</guid>
      <description>&lt;p&gt;A credit card number was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Debug Error Messages</title>
      <link>/docs/alerts/10023/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10023/</guid>
      <description>&lt;p&gt;The response appeared to contain common error messages returned by platforms such as ASP.NET, and Web-servers such as IIS and Apache. You can configure the list of common debug messages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Debug Error Messages via WebSocket</title>
      <link>/docs/alerts/110003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110003/</guid>
      <description>&lt;p&gt;The response appeared to contain common error messages returned by platforms such as ASP.NET, and Web-servers such as IIS and Apache. You can configure the list of common debug messages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Email Addresses</title>
      <link>/docs/alerts/100009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100009/</guid>
      <description>&lt;p&gt;An email address was found in the HTTP response body. Exposure of email addresses in HTTP messages can lead to privacy violations  and targeted phishing attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Google API Key</title>
      <link>/docs/alerts/100034/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100034/</guid>
      <description>&lt;p&gt;A Google API Key was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Hash</title>
      <link>/docs/alerts/100010/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100010/</guid>
      <description>&lt;p&gt;A hash was discovered in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - HTML Comments</title>
      <link>/docs/alerts/100011/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100011/</guid>
      <description>&lt;p&gt;While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - IBAN Numbers</title>
      <link>/docs/alerts/100012/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100012/</guid>
      <description>&lt;p&gt;An IBAN number was discovered in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Information in Browser localStorage</title>
      <link>/docs/alerts/120000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120000-1/</guid>
      <description>&lt;p&gt;Information was stored in browser localStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Information in Browser sessionStorage</title>
      <link>/docs/alerts/120000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120000-2/</guid>
      <description>&lt;p&gt;Information was stored in browser sessionStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Information in Browser Storage</title>
      <link>/docs/alerts/120000/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120000/</guid>
      <description></description>
    </item>
    <item>
      <title>Information Disclosure - IP Exposed via F5 BIG-IP Persistence Cookie</title>
      <link>/docs/alerts/100006/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100006/</guid>
      <description>&lt;p&gt;The F5 BIG-IP Persistence cookie set for this website can be decoded to a specific IP and port. An attacker may leverage this information to conduct Social Engineering attacks or other exploits.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Java Stack Trace</title>
      <link>/docs/alerts/100035/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100035/</guid>
      <description>&lt;p&gt;A Java stack trace was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - JWT in Browser localStorage</title>
      <link>/docs/alerts/120002-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120002-1/</guid>
      <description>&lt;p&gt;JWT was stored in browser localStorage.&#xA;This is dangerous because data stored in localStorage does not expire. .&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - JWT in Browser sessionStorage</title>
      <link>/docs/alerts/120002-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120002-2/</guid>
      <description>&lt;p&gt;JWT was stored in browser sessionStorage.&#xA;This is not unusual or necessarily unsafe - this informational alert has been raised to help you get a better understanding of what this app is doing. For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - JWT in Browser Storage</title>
      <link>/docs/alerts/120002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120002/</guid>
      <description></description>
    </item>
    <item>
      <title>Information Disclosure - Private IP Address</title>
      <link>/docs/alerts/100013/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100013/</guid>
      <description>&lt;p&gt;A private IP such as 10.x.x.x, 172.x.x.x, 192.168.x.x or IPV6 fe00:: has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Sensitive Information in Browser localStorage</title>
      <link>/docs/alerts/120001-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120001-1/</guid>
      <description>&lt;p&gt;Sensitive Information appears to have been stored in browser localStorage. This can violate PCI and most organizational compliance policies.&#xA;For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Sensitive Information in Browser sessionStorage</title>
      <link>/docs/alerts/120001-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120001-2/</guid>
      <description>&lt;p&gt;Sensitive Information appears to have been stored in browser sessionStorage. This can violate PCI and most organizational compliance policies.&#xA;For more details see the Client tabs - this information was set directly in the browser and will therefore not necessarily appear in this form in any HTTP(S) messages.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Sensitive Information in Browser Storage</title>
      <link>/docs/alerts/120001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/120001/</guid>
      <description></description>
    </item>
    <item>
      <title>Information Disclosure - Sensitive Information in HTTP Referrer Header</title>
      <link>/docs/alerts/10025/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10025/</guid>
      <description>&lt;p&gt;The HTTP header may have leaked a potentially sensitive parameter to another domain. This can violate PCI and most organizational compliance policies. You can configure the list of strings for this check to add or remove values specific to your environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Sensitive Information in URL</title>
      <link>/docs/alerts/10024/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10024/</guid>
      <description>&lt;p&gt;The request appeared to contain sensitive information leaked in the URL. This can violate PCI and most organizational compliance policies. You can configure the list of strings for this check to add or remove values specific to your environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Server Header</title>
      <link>/docs/alerts/100019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100019/</guid>
      <description>&lt;p&gt;The web/application server is leaking version information via the &amp;lsquo;Server&amp;rsquo; HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server  is subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - SQL Error</title>
      <link>/docs/alerts/100020/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100020/</guid>
      <description>&lt;p&gt;An SQL error was found in the HTTP response body.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Suspicious Comments</title>
      <link>/docs/alerts/10027/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10027/</guid>
      <description>&lt;p&gt;The response appears to contain suspicious comments which may help an attacker.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - Suspicious Comments in XML via WebSocket</title>
      <link>/docs/alerts/110008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110008/</guid>
      <description>&lt;p&gt;The response appears to contain suspicious comments which may help an attacker.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information Disclosure - X-Powered-By Header</title>
      <link>/docs/alerts/100023/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100023/</guid>
      <description>&lt;p&gt;The web/application server is leaking information via one or more &amp;lsquo;X-Powered-By&amp;rsquo; HTTP response headers. Access to such information may facilitate attackers identifying other frameworks/components your web application is reliant upon and the vulnerabilities such components may be subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Inline event handler built from dynamic data</title>
      <link>/docs/alerts/220000-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-6/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure HTTP Method</title>
      <link>/docs/alerts/90028/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90028/</guid>
      <description></description>
    </item>
    <item>
      <title>Insecure HTTP Method - CONNECT</title>
      <link>/docs/alerts/90028-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90028-4/</guid>
      <description>&lt;p&gt;The insecure HTTP method [CONNECT] is enabled for this resource, and is exploitable. It was found to be possible to establish a tunneled socket connection to a third party service, using this HTTP method. This would allow the service to be used as an anonymous spam relay, or as a web proxy, bypassing network restrictions. It also allows it to be used to establish a tunneled VPN, effectively extending the network perimeter to include untrusted components.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure HTTP Method - DELETE</title>
      <link>/docs/alerts/90028-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90028-1/</guid>
      <description>&lt;p&gt;The insecure HTTP method [DELETE] is enabled on the web server for this resource. Depending on the web server configuration, and the underlying implementation responsible for serving the resource, this might or might not be exploitable. The TRACK and TRACE methods may be used by an attacker, to gain access to the authorisation token/session cookie of an application user, even if the session cookie is protected using the HttpOnly flag. For the attack to be successful, the application user must typically be using an older web browser, or a web browser which has a Same Origin Policy (SOP) bypass vulnerability. The CONNECT method can be used by a web client to create an HTTP tunnel to third party websites or services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure HTTP Method - PROPFIND</title>
      <link>/docs/alerts/90028-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90028-5/</guid>
      <description>&lt;p&gt;This HTTP method is a WEBDAV method: PROPFIND. If this server is not offering any WEBDAV services, these methods should not be available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure HTTP Method - PUT</title>
      <link>/docs/alerts/90028-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90028-2/</guid>
      <description>&lt;p&gt;The insecure HTTP method [PUT] is enabled on the web server for this resource. Depending on the web server configuration, and the underlying implementation responsible for serving the resource, this might or might not be exploitable. The TRACK and TRACE methods may be used by an attacker, to gain access to the authorisation token/session cookie of an application user, even if the session cookie is protected using the HttpOnly flag. For the attack to be successful, the application user must typically be using an older web browser, or a web browser which has a Same Origin Policy (SOP) bypass vulnerability. The CONNECT method can be used by a web client to create an HTTP tunnel to third party websites or services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure HTTP Method - PUT</title>
      <link>/docs/alerts/90028-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90028-6/</guid>
      <description>&lt;p&gt;This method was originally intended for file management operations. It is now most commonly used in REST services, PUT is most-often utilized for &lt;strong&gt;update&lt;/strong&gt; capabilities, PUT-ing to a known resource URI with the request body containing the newly-updated representation of the original resource.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure HTTP Method - TRACE</title>
      <link>/docs/alerts/90028-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90028-3/</guid>
      <description>&lt;p&gt;The insecure HTTP method [TRACE] is enabled for this resource, and is exploitable. The TRACK and TRACE methods may be used by an attacker, to gain access to the authorisation token/session cookie of an application user, even if the session cookie is protected using the HttpOnly flag. For the attack to be successful, the application user must typically be using an older web browser, or a web browser which has a Same Origin Policy (SOP) bypass vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure JSF ViewState</title>
      <link>/docs/alerts/90001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90001/</guid>
      <description>&lt;p&gt;The response at the following URL contains a ViewState value that has no cryptographic protections.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insufficient Site Isolation Against Spectre Vulnerability</title>
      <link>/docs/alerts/90004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90004/</guid>
      <description></description>
    </item>
    <item>
      <title>Integer Overflow Error</title>
      <link>/docs/alerts/30003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/30003/</guid>
      <description>&lt;p&gt;An integer overflow condition exists when an integer used in a compiled program extends beyond the range limits and has not been properly checked from the input stream.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Internal file path disclosure</title>
      <link>/docs/alerts/200010-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-6/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Internal IP address leaked in response</title>
      <link>/docs/alerts/200016-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-1/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Java Serialization Object</title>
      <link>/docs/alerts/90002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90002/</guid>
      <description>&lt;p&gt;Java Serialization seems to be in use. If not correctly validated, an attacker can send a specially crafted object. This can lead to a dangerous &amp;ldquo;Remote Code Execution&amp;rdquo;. A magic sequence identifying JSO has been detected (Base64: rO0AB, Raw: 0xac, 0xed, 0x00, 0x05).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Java stack trace</title>
      <link>/docs/alerts/200010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-2/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JavaScript includes sourceMappingURL</title>
      <link>/docs/alerts/200009-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-1/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to form action</title>
      <link>/docs/alerts/210006-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-1/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to form action.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to formAction</title>
      <link>/docs/alerts/210006-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210006-2/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to formAction.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to href</title>
      <link>/docs/alerts/210003-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-1/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to href and likely to execute in the current browsing context.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to iframe.src</title>
      <link>/docs/alerts/210003-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-3/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to iframe.src.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL assigned to src</title>
      <link>/docs/alerts/210003-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-6/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to a generic src attribute and interpreted as executable content.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL navigated via location.assign</title>
      <link>/docs/alerts/210003-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-9/</guid>
      <description>&lt;p&gt;Tainted javascript: URL passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL navigated via location.href</title>
      <link>/docs/alerts/210003-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-2/</guid>
      <description>&lt;p&gt;Tainted javascript: URL assigned to location.href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL navigated via location.replace</title>
      <link>/docs/alerts/210003-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-11/</guid>
      <description>&lt;p&gt;Tainted javascript: URL passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>javascript: URL opened via window.open</title>
      <link>/docs/alerts/210003-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210003-13/</guid>
      <description>&lt;p&gt;Tainted javascript: URL passed to window.open.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JSONP callback parameter controls JavaScript response</title>
      <link>/docs/alerts/200024/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200024/</guid>
      <description>&lt;p&gt;Tests callback-like parameters for JSONP-style JavaScript responses where user input controls the executed callback name.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Authorization header)</title>
      <link>/docs/alerts/200003-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-6/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Cookie)</title>
      <link>/docs/alerts/200003-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-4/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (Form body param)</title>
      <link>/docs/alerts/200003-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-5/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm (JSON body)</title>
      <link>/docs/alerts/200003-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-7/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT None Algorithm attacks</title>
      <link>/docs/alerts/200003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003/</guid>
      <description></description>
    </item>
    <item>
      <title>JWT None Exploit</title>
      <link>/docs/alerts/100026/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100026/</guid>
      <description>&lt;p&gt;The application&amp;rsquo;s JWT implementation allows for the usage of the &amp;rsquo;none&amp;rsquo; algorithm, which bypasses the JWT hash verification.&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (Authorization &#43; JWT cookies removed)</title>
      <link>/docs/alerts/200003-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-1/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (Authorization header removed)</title>
      <link>/docs/alerts/200003-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-2/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Probe (JWT cookies removed)</title>
      <link>/docs/alerts/200003-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200003-3/</guid>
      <description>&lt;p&gt;This attack occurs when an attacker alters the token and changes the hashing algorithm to indicate, through the none keyword, that the integrity of the token has already been verified&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT Scan Rule</title>
      <link>/docs/alerts/40036/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40036/</guid>
      <description>&lt;p&gt;Scanner for finding vulnerabilities in JWT implementations.&lt;/p&gt;</description>
    </item>
    <item>
      <title>JWT-like value in URL</title>
      <link>/docs/alerts/200014-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200014-2/</guid>
      <description>&lt;p&gt;Detects access tokens, JWTs, and API keys present in URLs or query strings observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>LDAP Injection</title>
      <link>/docs/alerts/40015-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40015-2/</guid>
      <description>&lt;p&gt;LDAP Injection may be possible. It may be possible for an attacker to bypass authentication controls, and to view and modify arbitrary data in the LDAP directory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LDAP Injection</title>
      <link>/docs/alerts/40015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40015/</guid>
      <description></description>
    </item>
    <item>
      <title>LDAP Injection - activedirectory</title>
      <link>/docs/alerts/40015-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40015-1/</guid>
      <description>&lt;p&gt;LDAP Injection may be possible. It may be possible for an attacker to bypass authentication controls, and to view and modify arbitrary data in the LDAP directory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lit unsafeHTML taint flow</title>
      <link>/docs/alerts/220005-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-6/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>localhost/127.0.0.1 referenced in response</title>
      <link>/docs/alerts/200016-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016-2/</guid>
      <description>&lt;p&gt;Detects internal hostnames/IPs and environment hints (staging/dev/local) disclosed in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>location.assign redirect from tainted source</title>
      <link>/docs/alerts/210019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-2/</guid>
      <description>&lt;p&gt;Tainted value passed to location.assign.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>location.href redirect from tainted source</title>
      <link>/docs/alerts/210019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-1/</guid>
      <description>&lt;p&gt;Tainted value navigated location.href.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>location.replace redirect from tainted source</title>
      <link>/docs/alerts/210019-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-3/</guid>
      <description>&lt;p&gt;Tainted value passed to location.replace.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Log4Shell</title>
      <link>/docs/alerts/40043/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40043/</guid>
      <description></description>
    </item>
    <item>
      <title>Log4Shell (CVE-2021-44228)</title>
      <link>/docs/alerts/40043-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40043-1/</guid>
      <description>&lt;p&gt;Apache Log4j2 &amp;lt;=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Log4Shell (CVE-2021-45046)</title>
      <link>/docs/alerts/40043-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40043-2/</guid>
      <description>&lt;p&gt;It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Loosely Scoped Cookie</title>
      <link>/docs/alerts/90033/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90033/</guid>
      <description>&lt;p&gt;Cookies can be scoped by domain or path. This check is only concerned with domain scope.The domain scope applied to a cookie determines which domains can access it. For example, a cookie can be scoped strictly to a subdomain e.g. &lt;a href=&#34;http://www.nottrusted.com&#34;&gt;www.nottrusted.com&lt;/a&gt;, or loosely scoped to a parent domain e.g. nottrusted.com. In the latter case, any subdomain of nottrusted.com can access the cookie. Loosely scoped cookies are common in mega-applications like google.com and live.com. Cookies set from a subdomain like app.foo.bar are transmitted only to that domain by the browser. However, cookies scoped to a parent-level domain may be transmitted to the parent, or any subdomain of the parent.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mapbox token exposed</title>
      <link>/docs/alerts/200011-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-8/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Message handler without origin validation</title>
      <link>/docs/alerts/220008-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-7/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing Anti-clickjacking Header</title>
      <link>/docs/alerts/10020-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10020-1/</guid>
      <description>&lt;p&gt;The response does not protect against &amp;lsquo;ClickJacking&amp;rsquo; attacks. It should include either Content-Security-Policy with &amp;lsquo;frame-ancestors&amp;rsquo; directive or X-Frame-Options.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing Content-Security-Policy header</title>
      <link>/docs/alerts/200005-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-1/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing or invalid X-Content-Type-Options</title>
      <link>/docs/alerts/200005-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-10/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing or weak Referrer-Policy</title>
      <link>/docs/alerts/200005-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-16/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing Security Headers</title>
      <link>/docs/alerts/100016/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100016/</guid>
      <description>&lt;p&gt;Some of the following security headers are missing from the HTTP response: Strict-Transport-Security, Content-Security-Policy, X-XSS-Protection, X-Content-Type-Options, X-Frame-Options.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing Strict-Transport-Security header (on HTTPS)</title>
      <link>/docs/alerts/200005-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-5/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Modern Web Application</title>
      <link>/docs/alerts/10109/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10109/</guid>
      <description>&lt;p&gt;The application appears to be a modern web application. If you need to explore it automatically then the Ajax Spider may well be more effective than the standard one.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple HREFs Redirect Detected (Potential Sensitive Information Leak)</title>
      <link>/docs/alerts/10044-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10044-2/</guid>
      <description>&lt;p&gt;The server has responded with a redirect that seems to contain multiple links. This may indicate that although the server sent a redirect it also responded with body content links (which may include sensitive details, PII, lead to admin panels, etc.).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple X-Frame-Options Header Entries</title>
      <link>/docs/alerts/10020-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10020-2/</guid>
      <description>&lt;p&gt;X-Frame-Options (XFO) headers were found, a response with multiple XFO header entries may not be predictably treated by all user-agents.&lt;/p&gt;</description>
    </item>
    <item>
      <title>navigation.navigate redirect from tainted source</title>
      <link>/docs/alerts/210019-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-5/</guid>
      <description>&lt;p&gt;Tainted value passed to navigation.navigate.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Network Destination Poisoning</title>
      <link>/docs/alerts/220006/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006/</guid>
      <description></description>
    </item>
    <item>
      <title>Next.js build metadata exposed</title>
      <link>/docs/alerts/200009-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-4/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Node.js / Express stack trace</title>
      <link>/docs/alerts/200010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-1/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Non Static Site Detected</title>
      <link>/docs/alerts/100017/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100017/</guid>
      <description>&lt;p&gt;A query string or form has been detected in the HTTP response body. This indicates that this may not be a static site.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Non-Storable Content</title>
      <link>/docs/alerts/10049-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10049-1/</guid>
      <description>&lt;p&gt;The response contents are not storable by caching components such as proxy servers. If the response does not contain sensitive, personal or user-specific information, it may benefit from being stored and cached, to improve performance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>NoSQL Injection - MongoDB</title>
      <link>/docs/alerts/40033/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40033/</guid>
      <description>&lt;p&gt;MongoDB query injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>NoSQL Injection - MongoDB (Time Based)</title>
      <link>/docs/alerts/90039/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90039/</guid>
      <description>&lt;p&gt;MongoDB query injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Obsolete Content Security Policy (CSP) Header Found</title>
      <link>/docs/alerts/10038-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10038-2/</guid>
      <description>&lt;p&gt;The &amp;ldquo;X-Content-Security-Policy&amp;rdquo; and &amp;ldquo;X-WebKit-CSP&amp;rdquo; headers are no longer recommended.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Off-site Redirect</title>
      <link>/docs/alerts/10028/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10028/</guid>
      <description>&lt;p&gt;Open redirects are one of the OWASP 2010 Top Ten vulnerabilities. This check looks at user-supplied input in query string parameters and POST data to identify where open redirects might be possible. Open redirects occur when an application allows user-supplied input (e.g. &lt;a href=&#34;https://nottrusted.com&#34;&gt;https://nottrusted.com&lt;/a&gt;) to control an off-site destination. This is generally a pretty accurate way to find where 301 or 302 redirects could be exploited by spammers or phishing attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OIDC well-known configuration observed</title>
      <link>/docs/alerts/200013-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-2/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Old Asp.Net Version in Use</title>
      <link>/docs/alerts/10032-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-3/</guid>
      <description>&lt;p&gt;This website uses ASP.NET version 1.0 or 1.1.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Redirect (generic)</title>
      <link>/docs/alerts/200023/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200023/</guid>
      <description></description>
    </item>
    <item>
      <title>Open redirect candidate parameter</title>
      <link>/docs/alerts/200015-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-1/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect from client-side taint sources</title>
      <link>/docs/alerts/210019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019/</guid>
      <description></description>
    </item>
    <item>
      <title>Open redirect reflected in body destination</title>
      <link>/docs/alerts/200023-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200023-3/</guid>
      <description>&lt;p&gt;Tests for open redirect by forcing redirect-like parameters to an external, benign domain.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect reflected in form action</title>
      <link>/docs/alerts/200023-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200023-2/</guid>
      <description>&lt;p&gt;Tests for open redirect by forcing redirect-like parameters to an external, benign domain.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect via common param names</title>
      <link>/docs/alerts/200023-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200023-1/</guid>
      <description>&lt;p&gt;Tests for open redirect by forcing redirect-like parameters to an external, benign domain.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect via Navigation API</title>
      <link>/docs/alerts/210002-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210002-2/</guid>
      <description>&lt;p&gt;Tainted destination URL used in navigation.navigate.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open redirect via window.open</title>
      <link>/docs/alerts/210002-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210002-1/</guid>
      <description>&lt;p&gt;Tainted URL used in window.open (possible open redirect).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Redirection</title>
      <link>/docs/alerts/220002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220002/</guid>
      <description></description>
    </item>
    <item>
      <title>OpenAPI spec detected</title>
      <link>/docs/alerts/200012-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-2/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Origin check uses host fragment only</title>
      <link>/docs/alerts/220008-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-5/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>OS Command Injection - Unix cat /etc/passwd (pipe)</title>
      <link>/docs/alerts/200001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200001/</guid>
      <description>&lt;p&gt;OS command injection (also known as shell injection) is a web security vulnerability that allows an attacker to execute arbitrary operating system (OS) commands on the server that is running an application, and typically fully compromise the application and all its data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Out of Band XSS</title>
      <link>/docs/alerts/40031/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40031/</guid>
      <description>&lt;p&gt;Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user&amp;rsquo;s browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.&#xA;When an attacker gets a user&amp;rsquo;s browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OWASP Secure Headers</title>
      <link>/docs/alerts/200005/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005/</guid>
      <description></description>
    </item>
    <item>
      <title>Parameter Tampering</title>
      <link>/docs/alerts/40008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40008/</guid>
      <description>&lt;p&gt;Parameter manipulation caused an error page or Java stack trace to be displayed. This indicated lack of exception handling and potential areas for further exploit.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Passive Recon: .well-known &amp; Metadata Files</title>
      <link>/docs/alerts/200013/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: API Docs &amp; Specs Exposure</title>
      <link>/docs/alerts/200012/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: Client Config &amp; Secret-Like Values</title>
      <link>/docs/alerts/200011/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: CORS Posture Indicators</title>
      <link>/docs/alerts/200017/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200017/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: Error &amp; Stack Trace Disclosure</title>
      <link>/docs/alerts/200010/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: High-Risk Parameter Names</title>
      <link>/docs/alerts/200015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: Interesting Endpoint Patterns</title>
      <link>/docs/alerts/200019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: Internal Hosts &amp; Environment Hints</title>
      <link>/docs/alerts/200016/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200016/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: Source Maps &amp; Debug Artifacts</title>
      <link>/docs/alerts/200009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009/</guid>
      <description></description>
    </item>
    <item>
      <title>Passive Recon: Tokens &amp; Secrets in URLs</title>
      <link>/docs/alerts/200014/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200014/</guid>
      <description></description>
    </item>
    <item>
      <title>Path Traversal</title>
      <link>/docs/alerts/6-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/6-1/</guid>
      <description>&lt;p&gt;The Path Traversal attack technique allows an attacker access to files, directories, and commands that potentially reside outside the web document root directory. An attacker may manipulate a URL in such a way that the web site will execute or reveal the contents of arbitrary files anywhere on the web server. Any device that exposes an HTTP-based interface is potentially vulnerable to Path Traversal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Path Traversal</title>
      <link>/docs/alerts/6-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/6-2/</guid>
      <description>&lt;p&gt;The Path Traversal attack technique allows an attacker access to files, directories, and commands that potentially reside outside the web document root directory. An attacker may manipulate a URL in such a way that the web site will execute or reveal the contents of arbitrary files anywhere on the web server. Any device that exposes an HTTP-based interface is potentially vulnerable to Path Traversal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Path Traversal</title>
      <link>/docs/alerts/6-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/6-3/</guid>
      <description>&lt;p&gt;The Path Traversal attack technique allows an attacker access to files, directories, and commands that potentially reside outside the web document root directory. An attacker may manipulate a URL in such a way that the web site will execute or reveal the contents of arbitrary files anywhere on the web server. Any device that exposes an HTTP-based interface is potentially vulnerable to Path Traversal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Path Traversal</title>
      <link>/docs/alerts/6-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/6-4/</guid>
      <description>&lt;p&gt;The Path Traversal attack technique allows an attacker access to files, directories, and commands that potentially reside outside the web document root directory. An attacker may manipulate a URL in such a way that the web site will execute or reveal the contents of arbitrary files anywhere on the web server. Any device that exposes an HTTP-based interface is potentially vulnerable to Path Traversal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Path Traversal</title>
      <link>/docs/alerts/6-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/6-5/</guid>
      <description>&lt;p&gt;The Path Traversal attack technique allows an attacker access to files, directories, and commands that potentially reside outside the web document root directory. An attacker may manipulate a URL in such a way that the web site will execute or reveal the contents of arbitrary files anywhere on the web server. Any device that exposes an HTTP-based interface is potentially vulnerable to Path Traversal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Path Traversal</title>
      <link>/docs/alerts/6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/6/</guid>
      <description></description>
    </item>
    <item>
      <title>Permissions Policy Header Not Set</title>
      <link>/docs/alerts/10063-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10063-1/</guid>
      <description>&lt;p&gt;Permissions Policy Header is an added layer of security that helps to restrict from unauthorized access or usage of browser/client features by web resources. This policy ensures the user privacy by limiting or specifying the features of the browsers can be used by the web resources. Permissions Policy provides a set of standard HTTP headers that allow website owners to limit which features of browsers can be used by the page such as camera, microphone, location, full screen etc.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Permissions Policy Header Not Set</title>
      <link>/docs/alerts/10063/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10063/</guid>
      <description></description>
    </item>
    <item>
      <title>Personally Identifiable Information via WebSocket</title>
      <link>/docs/alerts/110005/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110005/</guid>
      <description>&lt;p&gt;The response contains Personally Identifiable Information, such as CC number. Credit Card type detected: undefined.&lt;/p&gt;</description>
    </item>
    <item>
      <title>PHP fatal error / warning</title>
      <link>/docs/alerts/200010-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-5/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>phpinfo endpoint observed</title>
      <link>/docs/alerts/200019-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-9/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>PII Disclosure</title>
      <link>/docs/alerts/10062/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10062/</guid>
      <description>&lt;p&gt;The response contains Personally Identifiable Information, such as CC number, SSN and similar sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Possible Username Enumeration</title>
      <link>/docs/alerts/40023/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40023/</guid>
      <description>&lt;p&gt;It may be possible to enumerate usernames, based on differing HTTP responses when valid and invalid usernames are provided. This would greatly increase the probability of success of password brute-forcing attacks against the system. Note that false positives may sometimes be minimised by increasing the &amp;lsquo;Attack Strength&amp;rsquo; Option in ZAP. Please manually check the &amp;lsquo;Other Info&amp;rsquo; field to confirm if this is actually an issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>postMessage to cross-origin target with tainted payload</title>
      <link>/docs/alerts/210010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210010-2/</guid>
      <description>&lt;p&gt;Tainted data sent via window.postMessage to a different origin.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>postMessage to wildcard origin with tainted payload</title>
      <link>/docs/alerts/210010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210010-1/</guid>
      <description>&lt;p&gt;Tainted data sent via window.postMessage to wildcard &amp;lsquo;*&amp;rsquo; targetOrigin.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential .git exposure path observed</title>
      <link>/docs/alerts/200019-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-8/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential backup file observed</title>
      <link>/docs/alerts/200019-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-6/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potential IP Addresses Found in the Viewstate</title>
      <link>/docs/alerts/10032-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-1/</guid>
      <description>&lt;p&gt;Potential IP addresses were found being serialized in the viewstate field.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Potentially authenticated content lacks no-store</title>
      <link>/docs/alerts/200005-21/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-21/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Private IP Disclosure</title>
      <link>/docs/alerts/2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/2/</guid>
      <description>&lt;p&gt;A private IP (such as 10.x.x.x, 172.x.x.x, 192.168.x.x) or an Amazon EC2 private hostname (for example, ip-10-0-56-78) has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Private IP Disclosure via WebSocket</title>
      <link>/docs/alerts/110006/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110006/</guid>
      <description>&lt;p&gt;A private IP (such as 10.x.x.x, 172.x.x.x, 192.168.x.x) or an Amazon EC2 private hostname (for example, ip-10-0-56-78) has been found in the incoming WebSocket message. This information might be helpful for further attacks targeting internal systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Private key material exposed</title>
      <link>/docs/alerts/200011-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-1/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Properties File Disclosure - /WEB-INF folder</title>
      <link>/docs/alerts/10045-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10045-2/</guid>
      <description>&lt;p&gt;A Java class in the /WEB-INF folder disclosed the presence of the properties file. Properties file are not intended to be publicly accessible, and typically contain configuration information, application credentials, or cryptographic keys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Prototype pollution impact confirmation</title>
      <link>/docs/alerts/210008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210008/</guid>
      <description></description>
    </item>
    <item>
      <title>Prototype pollution influenced fetch() init</title>
      <link>/docs/alerts/210008-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210008-1/</guid>
      <description>&lt;p&gt;A prior tainted prototype write influenced inherited fetch() init fields.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Proxy Disclosure</title>
      <link>/docs/alerts/40025-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40025-1/</guid>
      <description>&lt;p&gt;1 proxy server(s) were detected or fingerprinted. This information helps a potential attacker to determine&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A list of targets for an attack against the application.&lt;/li&gt;&#xA;&lt;li&gt;Potential vulnerabilities on the proxy servers that service the application.&lt;/li&gt;&#xA;&lt;li&gt;The presence or absence of any proxy-based components that might cause attacks against the application to be detected, prevented, or mitigated.&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Proxy Disclosure</title>
      <link>/docs/alerts/40025-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40025-2/</guid>
      <description>&lt;p&gt;1 proxy server(s) were detected or fingerprinted. This information helps a potential attacker to determine&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A list of targets for an attack against the application.&lt;/li&gt;&#xA;&lt;li&gt;Potential vulnerabilities on the proxy servers that service the application.&lt;/li&gt;&#xA;&lt;li&gt;The presence or absence of any proxy-based components that might cause attacks against the application to be detected, prevented, or mitigated.&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Proxy Disclosure</title>
      <link>/docs/alerts/40025/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40025/</guid>
      <description></description>
    </item>
    <item>
      <title>Public-Key-Pins is deprecated</title>
      <link>/docs/alerts/200005-22/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-22/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Python traceback</title>
      <link>/docs/alerts/200010-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200010-4/</guid>
      <description>&lt;p&gt;Detects common framework stack traces, error pages, and path disclosures in observed responses.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Re-examine Cache-control Directives</title>
      <link>/docs/alerts/10015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10015/</guid>
      <description>&lt;p&gt;The cache-control header has not been set properly or is missing, allowing the browser and proxies to cache content. For static assets like css, js, or image files this might be intended, however, the resources should be reviewed to ensure that no sensitive content will be cached.&lt;/p&gt;</description>
    </item>
    <item>
      <title>React dangerouslySetInnerHTML taint flow</title>
      <link>/docs/alerts/220005-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-5/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Referer Exposes Session ID</title>
      <link>/docs/alerts/3-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/3-3/</guid>
      <description>&lt;p&gt;A hyperlink pointing to another host name was found. As session ID URL rewrite is used, it may be disclosed in referer header to external hosts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflected Cross-Site Scripting (XSS)</title>
      <link>/docs/alerts/200002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002/</guid>
      <description></description>
    </item>
    <item>
      <title>Reflected HTTP GET Parameter(s)</title>
      <link>/docs/alerts/100014/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100014/</guid>
      <description>&lt;p&gt;A reflected parameter value has been found in the HTTP response. Reflected parameter values may introduce XSS vulnerability or HTTP header injection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Relative Path Confusion</title>
      <link>/docs/alerts/10051/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10051/</guid>
      <description>&lt;p&gt;The web server is configured to serve responses to ambiguous URLs in a manner that is likely to lead to confusion about the correct &amp;ldquo;relative path&amp;rdquo; for the URL. Resources (CSS, images, etc.) are also specified in the page response using relative, rather than absolute URLs. In an attack, if the web browser parses the &amp;ldquo;cross-content&amp;rdquo; response in a permissive manner, or can be tricked into permissively parsing the &amp;ldquo;cross-content&amp;rdquo; response, using techniques such as framing, then the web browser may be fooled into interpreting HTML as CSS (or other content types), leading to an XSS vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Relative Path Overwrite</title>
      <link>/docs/alerts/100018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100018/</guid>
      <description>&lt;p&gt;Potential RPO (Relative Path Overwrite) found. RPO allows attackers to manipulate URLs to include unintended paths, potentially leading to the execution of malicious scripts or the disclosure of sensitive information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote Code Execution - CVE-2012-1823</title>
      <link>/docs/alerts/20018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20018/</guid>
      <description>&lt;p&gt;Some PHP versions, when configured to run using CGI, do not correctly handle query strings that lack an unescaped &amp;ldquo;=&amp;rdquo; character, enabling arbitrary code execution. In this case, an operating system command was caused to be executed on the web server, and the results were returned to the web browser.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote Code Execution - Shell Shock</title>
      <link>/docs/alerts/10048-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10048-1/</guid>
      <description>&lt;p&gt;The server is running a version of the Bash shell that allows remote attackers to execute arbitrary code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote Code Execution - Shell Shock</title>
      <link>/docs/alerts/10048-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10048-2/</guid>
      <description>&lt;p&gt;The server is running a version of the Bash shell that allows remote attackers to execute arbitrary code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote Code Execution - Shell Shock</title>
      <link>/docs/alerts/10048/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10048/</guid>
      <description></description>
    </item>
    <item>
      <title>Remote Code Execution (React2Shell)</title>
      <link>/docs/alerts/40048/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40048/</guid>
      <description>&lt;p&gt;The server is running Next.js and vulnerable versions of React Server Components with Next.js which allow remote attackers to execute arbitrary code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote File Inclusion</title>
      <link>/docs/alerts/7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/7/</guid>
      <description>&lt;p&gt;Remote File Include (RFI) is an attack technique used to exploit &amp;ldquo;dynamic file include&amp;rdquo; mechanisms in web applications. When web applications take user input (URL, parameter value, etc.) and pass them into file include commands, the web application might be tricked into including remote files with malicious code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote OS Command Injection</title>
      <link>/docs/alerts/90020/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90020/</guid>
      <description>&lt;p&gt;Attack technique used for unauthorized execution of operating system commands. This attack is possible when an application accepts untrusted input to build operating system commands in an insecure manner involving improper data sanitization, and/or improper calling of external programs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote OS Command Injection (Time Based)</title>
      <link>/docs/alerts/90037/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90037/</guid>
      <description>&lt;p&gt;Attack technique used for unauthorized execution of operating system commands. This attack is possible when an application accepts untrusted input to build operating system commands in an insecure manner involving improper data sanitization, and/or improper calling of external programs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field parsed via createContextualFragment</title>
      <link>/docs/alerts/210007-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-7/</guid>
      <description>&lt;p&gt;Response-derived HTML parsed via Range.createContextualFragment.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field parsed via DOMParser</title>
      <link>/docs/alerts/210007-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-6/</guid>
      <description>&lt;p&gt;Response-derived HTML parsed via DOMParser.parseFromString.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via document.write</title>
      <link>/docs/alerts/210007-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-2/</guid>
      <description>&lt;p&gt;Response-derived data reached document.write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via DOM mutation</title>
      <link>/docs/alerts/210007-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-5/</guid>
      <description>&lt;p&gt;Response-derived data reached DOM mutation sinks.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via innerHTML</title>
      <link>/docs/alerts/210007-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-1/</guid>
      <description>&lt;p&gt;Response-derived data reached innerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via insertAdjacentHTML</title>
      <link>/docs/alerts/210007-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-4/</guid>
      <description>&lt;p&gt;Response-derived HTML reached insertAdjacentHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via outerHTML</title>
      <link>/docs/alerts/210007-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-3/</guid>
      <description>&lt;p&gt;Response-derived data reached outerHTML.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via setHTMLUnsafe</title>
      <link>/docs/alerts/210007-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-8/</guid>
      <description>&lt;p&gt;Response-derived HTML reached Element.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response field rendered via ShadowRoot.setHTMLUnsafe</title>
      <link>/docs/alerts/210007-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007-9/</guid>
      <description>&lt;p&gt;Response-derived HTML reached ShadowRoot.setHTMLUnsafe.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Response-derived DOM execution reachability</title>
      <link>/docs/alerts/210007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210007/</guid>
      <description></description>
    </item>
    <item>
      <title>Retrieved from Cache</title>
      <link>/docs/alerts/10050-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10050-1/</guid>
      <description>&lt;p&gt;The content was retrieved from a shared cache. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Retrieved from Cache</title>
      <link>/docs/alerts/10050-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10050-2/</guid>
      <description>&lt;p&gt;The content was retrieved from a shared cache. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Retrieved from Cache</title>
      <link>/docs/alerts/10050/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10050/</guid>
      <description></description>
    </item>
    <item>
      <title>Reverse Tabnabbing</title>
      <link>/docs/alerts/10108/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10108/</guid>
      <description>&lt;p&gt;At least one link on this page is vulnerable to Reverse tabnabbing as it uses a target attribute without using both of the &amp;ldquo;noopener&amp;rdquo; and &amp;ldquo;noreferrer&amp;rdquo; keywords in the &amp;ldquo;rel&amp;rdquo; attribute, which allows the target page to take control of this page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review assignments to href/src/action</title>
      <link>/docs/alerts/220009-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220009-1/</guid>
      <description>&lt;p&gt;Detects DOM code that rewrites link destinations (href attributes) with attacker-controlled data. Manipulated links can mislead users into visiting malicious targets even if navigation is not forced automatically.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review direct Axios destination usage</title>
      <link>/docs/alerts/220006-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-4/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review DOMParser.parseFromString with dynamic HTML/XML</title>
      <link>/docs/alerts/220000-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-4/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review dynamic import usage</title>
      <link>/docs/alerts/220007-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-3/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review EventSource constructor usage</title>
      <link>/docs/alerts/220006-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-3/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review importScripts usage</title>
      <link>/docs/alerts/220007-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-7/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review jQuery getScript usage</title>
      <link>/docs/alerts/220007-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-1/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review message event listeners</title>
      <link>/docs/alerts/220008-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-6/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review sendBeacon body content</title>
      <link>/docs/alerts/220006-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-2/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review sendBeacon destination</title>
      <link>/docs/alerts/220006-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-1/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review serviceWorker.register usage</title>
      <link>/docs/alerts/220007-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-6/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review SharedWorker constructor usage</title>
      <link>/docs/alerts/220007-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-5/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review System.import usage</title>
      <link>/docs/alerts/220007-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-2/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review uses of appendChild</title>
      <link>/docs/alerts/220000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-2/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review Vue v-html template usage</title>
      <link>/docs/alerts/220005-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-3/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review Worker constructor usage</title>
      <link>/docs/alerts/220007-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-4/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Route-controlled client navigation</title>
      <link>/docs/alerts/210004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210004/</guid>
      <description></description>
    </item>
    <item>
      <title>Route-controlled history.pushState</title>
      <link>/docs/alerts/210004-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210004-3/</guid>
      <description>&lt;p&gt;Client route state influenced history.pushState.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Route-controlled history.replaceState</title>
      <link>/docs/alerts/210004-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210004-1/</guid>
      <description>&lt;p&gt;Client route state influenced history.replaceState.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Route-controlled Navigation API transition</title>
      <link>/docs/alerts/210004-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210004-2/</guid>
      <description>&lt;p&gt;Client route state influenced navigation.navigate.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Same-origin URL mutations</title>
      <link>/docs/alerts/220002-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220002-2/</guid>
      <description>&lt;p&gt;Detects client-side code that can redirect users to attacker-controlled URLs (open redirects). Includes assignment/calls that control window/location/navigation, attr-based redirects, form actions and jQuery variants.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>SameSite Cookie Attribute Protection Used</title>
      <link>/docs/alerts/100005/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100005/</guid>
      <description></description>
    </item>
    <item>
      <title>Script Served From Malicious Domain (polyfill)</title>
      <link>/docs/alerts/10115-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10115-1/</guid>
      <description>&lt;p&gt;The page includes one or more script files loaded from one of the &amp;lsquo;polyfill&amp;rsquo; domains.&#xA;These are not associated with the polyfill.js library and are known to serve malicious content.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Script Served From Malicious Domain (polyfill)</title>
      <link>/docs/alerts/10115-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10115-2/</guid>
      <description>&lt;p&gt;The page includes one or more script which appear to include a reference to one of the &amp;lsquo;polyfill&amp;rsquo; domains.&#xA;These are not associated with the polyfill.js library and are known to serve malicious content.&#xA;You should check to see if it is a safe reference (for example in a comment) or whether the script is loading content from that domain.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Script Served From Malicious Domain (polyfill)</title>
      <link>/docs/alerts/10115/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10115/</guid>
      <description></description>
    </item>
    <item>
      <title>Sec-Fetch-Dest Header Has an Invalid Value</title>
      <link>/docs/alerts/90005-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-7/</guid>
      <description>&lt;p&gt;Specifies how and where the data would be used. For instance, if the value is audio, then the requested resource must be audio data and not any other type of resource.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sec-Fetch-Dest Header is Missing</title>
      <link>/docs/alerts/90005-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-3/</guid>
      <description>&lt;p&gt;Specifies how and where the data would be used. For instance, if the value is audio, then the requested resource must be audio data and not any other type of resource.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sec-Fetch-Mode Header Has an Invalid Value</title>
      <link>/docs/alerts/90005-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-6/</guid>
      <description>&lt;p&gt;Allows to differentiate between requests for navigating between HTML pages and requests for loading resources like images, audio etc.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sec-Fetch-Mode Header is Missing</title>
      <link>/docs/alerts/90005-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-2/</guid>
      <description>&lt;p&gt;Allows to differentiate between requests for navigating between HTML pages and requests for loading resources like images, audio etc.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sec-Fetch-Site Header Has an Invalid Value</title>
      <link>/docs/alerts/90005-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-5/</guid>
      <description>&lt;p&gt;Specifies the relationship between request initiator&amp;rsquo;s origin and target&amp;rsquo;s origin.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sec-Fetch-Site Header is Missing</title>
      <link>/docs/alerts/90005-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-1/</guid>
      <description>&lt;p&gt;Specifies the relationship between request initiator&amp;rsquo;s origin and target&amp;rsquo;s origin.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sec-Fetch-User Header Has an Invalid Value</title>
      <link>/docs/alerts/90005-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-8/</guid>
      <description>&lt;p&gt;Specifies if a navigation request was initiated by a user.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sec-Fetch-User Header is Missing</title>
      <link>/docs/alerts/90005-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90005-4/</guid>
      <description>&lt;p&gt;Specifies if a navigation request was initiated by a user.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secure Pages Include Mixed Content</title>
      <link>/docs/alerts/10040/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10040/</guid>
      <description>&lt;p&gt;The page includes mixed content, that is content accessed via HTTP instead of HTTPS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>security.txt observed</title>
      <link>/docs/alerts/200013-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200013-1/</guid>
      <description>&lt;p&gt;Flags security-relevant well-known resources and metadata files when they appear in observed traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sensitive cookies missing security flags</title>
      <link>/docs/alerts/200005-20/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-20/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sensitive data exposure</title>
      <link>/docs/alerts/200006/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200006/</guid>
      <description></description>
    </item>
    <item>
      <title>Sentry DSN exposed</title>
      <link>/docs/alerts/200011-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-5/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server banner discloses software/version</title>
      <link>/docs/alerts/200005-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-9/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server is running on Clacks - GNU Terry Pratchett</title>
      <link>/docs/alerts/100002/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100002/</guid>
      <description>&lt;p&gt;The web/application server is running over the Clacks network, some say it&amp;rsquo;s turtles/IP,  some say it&amp;rsquo;s turtles all the way down the layer stack.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Leaks Information via &#34;X-Powered-By&#34; HTTP Response Header Field(s)</title>
      <link>/docs/alerts/10037/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10037/</guid>
      <description>&lt;p&gt;The web/application server is leaking information via one or more &amp;ldquo;X-Powered-By&amp;rdquo; HTTP response headers. Access to such information may facilitate attackers identifying other frameworks/components your web application is reliant upon and the vulnerabilities such components may be subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Leaks its Webserver Application via &#34;Server&#34; HTTP Response Header Field</title>
      <link>/docs/alerts/10036-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10036-1/</guid>
      <description>&lt;p&gt;The web/application server is leaking the application it uses as a webserver via the &amp;ldquo;Server&amp;rdquo; HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server is subject to. This information alone, i.e. without a version string, is not very dangerous for the security of a server, nevertheless this information in the response header field is almost always useless and thus just an obsolete attacking vector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Leaks Version Information via &#34;Server&#34; HTTP Response Header Field</title>
      <link>/docs/alerts/10036-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10036-2/</guid>
      <description>&lt;p&gt;The web/application server is leaking version information via the &amp;ldquo;Server&amp;rdquo; HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server is subject to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Side Code Injection</title>
      <link>/docs/alerts/90019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90019/</guid>
      <description></description>
    </item>
    <item>
      <title>Server Side Code Injection - ASP Code Injection</title>
      <link>/docs/alerts/90019-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90019-2/</guid>
      <description>&lt;p&gt;A code injection may be possible including custom code that will be evaluated by the scripting engine.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Side Code Injection - PHP Code Injection</title>
      <link>/docs/alerts/90019-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90019-1/</guid>
      <description>&lt;p&gt;A code injection may be possible including custom code that will be evaluated by the scripting engine.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Side Include</title>
      <link>/docs/alerts/40009/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40009/</guid>
      <description>&lt;p&gt;Certain parameters may cause Server Side Include commands to be executed. This may allow database connection or arbitrary code to be executed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Side Request Forgery</title>
      <link>/docs/alerts/40046/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40046/</guid>
      <description>&lt;p&gt;The web server receives a remote address and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Side Template Injection</title>
      <link>/docs/alerts/90035/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90035/</guid>
      <description>&lt;p&gt;When the user input is inserted in the template instead of being used as argument in rendering is evaluated by the template engine. Depending on the template engine it can lead to remote code execution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Server Side Template Injection (Blind)</title>
      <link>/docs/alerts/90036/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90036/</guid>
      <description>&lt;p&gt;When the user input is inserted in the template instead of being used as argument in rendering is evaluated by the template engine. Depending on the template engine it can lead to remote code execution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session Fixation</title>
      <link>/docs/alerts/40013-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40013-4/</guid>
      <description>&lt;p&gt;Session Fixation may be possible. If this issue occurs with a login URL (where the user authenticates themselves to the application), then the URL may be given by an attacker, along with a fixed session id, to a victim, in order to later assume the identity of the victim using the given session id. If the issue occurs with a non-login page, the URL and fixed session id may only be used by an attacker to track an unauthenticated user&amp;rsquo;s actions. If the vulnerability occurs on a cookie field or a form field (POST parameter) rather than on a URL (GET) parameter, then some other vulnerability may also be required in order to set the cookie field on the victim&amp;rsquo;s browser, to allow the vulnerability to be exploited.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session Fixation</title>
      <link>/docs/alerts/40013-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40013-6/</guid>
      <description>&lt;p&gt;Session Fixation may be possible. If this issue occurs with a login URL (where the user authenticates themselves to the application), then the URL may be given by an attacker, along with a fixed session id, to a victim, in order to later assume the identity of the victim using the given session id. If the issue occurs with a non-login page, the URL and fixed session id may only be used by an attacker to track an unauthenticated user&amp;rsquo;s actions. If the vulnerability occurs on a cookie field or a form field (POST parameter) rather than on a URL (GET) parameter, then some other vulnerability may also be required in order to set the cookie field on the victim&amp;rsquo;s browser, to allow the vulnerability to be exploited.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session Fixation</title>
      <link>/docs/alerts/40013/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40013/</guid>
      <description></description>
    </item>
    <item>
      <title>Session ID Cookie Accessible to JavaScript</title>
      <link>/docs/alerts/40013-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40013-2/</guid>
      <description>&lt;p&gt;A Session Id cookie sent by the server (when the URL is modified by setting the named parameter field to NULL) may be accessed by JavaScript on the client. In conjunction with another vulnerability, this may allow the session to be hijacked.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session ID Expiry Time/Max-Age is Excessive</title>
      <link>/docs/alerts/40013-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40013-3/</guid>
      <description>&lt;p&gt;A Session Id cookie sent by the server (when the URL is modified by setting the named parameter field to NULL) is set to be valid for an excessive period of time. This may be exploitable by an attacker if the user forgets to log out, if the logout functionality does not correctly destroy the session, or if the session id is compromised by some other means.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session ID in URL Rewrite</title>
      <link>/docs/alerts/3-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/3-1/</guid>
      <description>&lt;p&gt;URL rewrite is used to track user session ID. The session ID may be disclosed via cross-site referer header. In addition, the session ID might be stored in browser history or server logs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session ID in URL Rewrite</title>
      <link>/docs/alerts/3-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/3-2/</guid>
      <description>&lt;p&gt;URL rewrite is used to track user session ID. The session ID may be disclosed via cross-site referer header. In addition, the session ID might be stored in browser history or server logs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session ID in URL Rewrite</title>
      <link>/docs/alerts/3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/3/</guid>
      <description></description>
    </item>
    <item>
      <title>Session ID Transmitted Insecurely</title>
      <link>/docs/alerts/40013-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40013-1/</guid>
      <description>&lt;p&gt;A session id may be sent via an insecure mechanism. In the case of a cookie sent in the request, this occurs when HTTP, rather than HTTPS, is used. In the case of a cookie sent by the server in response (when the URL is modified by setting the named parameter field to NULL), the &amp;lsquo;secure&amp;rsquo; flag is not set, allowing the cookie to be sent later via HTTP rather than via HTTPS. This may allow a passive eavesdropper on the network path to gain full access to the victim&amp;rsquo;s session.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Session Management Response Identified</title>
      <link>/docs/alerts/10112/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10112/</guid>
      <description>&lt;p&gt;The given response has been identified as containing a session management token. The &amp;lsquo;Other Info&amp;rsquo; field contains a set of header tokens that can be used in the Header Based Session Management Method. If the request is in a context which has a Session Management Method set to &amp;ldquo;Auto-Detect&amp;rdquo; then this rule will change the session management to use the tokens identified.&lt;/p&gt;</description>
    </item>
    <item>
      <title>setInterval(string) from storage/referrer taint</title>
      <link>/docs/alerts/210018-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-5/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached setInterval(string).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>setTimeout(string) from storage/referrer taint</title>
      <link>/docs/alerts/210018-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018-4/</guid>
      <description>&lt;p&gt;Storage/referrer taint reached setTimeout(string).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Slack token pattern</title>
      <link>/docs/alerts/200011-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-3/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>SOAP Action Spoofing</title>
      <link>/docs/alerts/90026/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90026/</guid>
      <description>&lt;p&gt;An unintended SOAP operation was executed by the server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SOAP XML Injection</title>
      <link>/docs/alerts/90029/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90029/</guid>
      <description>&lt;p&gt;Some XML injected code has been interpreted by the server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Social Security Number</title>
      <link>/docs/alerts/200006-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200006-2/</guid>
      <description>&lt;p&gt;Sensitive data is anything that should not be accessible to admin access, known as sensitive data. Sensitive data may include personally identifiable information (PII), such as Social Security numbers, financial information, or login credentials. Sensitive Data Exposure occurs when an organization unknowingly exposes sensitive data or when a security incident leads to the accidental or unlawful destruction, loss, alteration, or admin disclosure of, or access to sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - /WEB-INF Folder</title>
      <link>/docs/alerts/10045-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10045-1/</guid>
      <description>&lt;p&gt;Java source code was disclosed by the web server in Java class files in the WEB-INF folder. The class files can be dis-assembled to produce source code which very closely matches the original source code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - /WEB-INF Folder</title>
      <link>/docs/alerts/10045/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10045/</guid>
      <description></description>
    </item>
    <item>
      <title>Source Code Disclosure - CVE-2012-1823</title>
      <link>/docs/alerts/20017/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/20017/</guid>
      <description>&lt;p&gt;Some PHP versions, when configured to run using CGI, do not correctly handle query strings that lack an unescaped &amp;ldquo;=&amp;rdquo; character, enabling PHP source code disclosure, and arbitrary code execution. In this case, the contents of the PHP file were served directly to the web browser. This output will typically contain PHP, although it may also contain straight HTML.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - File Inclusion</title>
      <link>/docs/alerts/43/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/43/</guid>
      <description>&lt;p&gt;The Path Traversal attack technique allows an attacker access to files, directories, and commands that potentially reside outside the web document root directory. An attacker may manipulate a URL in such a way that the web site will execute or reveal the contents of arbitrary files anywhere on the web server. Any device that exposes an HTTP-based interface is potentially vulnerable to Path Traversal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - Git</title>
      <link>/docs/alerts/41/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/41/</guid>
      <description>&lt;p&gt;The source code for the current page was disclosed by the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - PHP</title>
      <link>/docs/alerts/10099/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10099/</guid>
      <description>&lt;p&gt;Application Source Code was disclosed by the web server. - PHP&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - SVN</title>
      <link>/docs/alerts/42/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/42/</guid>
      <description>&lt;p&gt;The source code for the current page was disclosed by the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SPA hash DOM XSS</title>
      <link>/docs/alerts/200007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200007/</guid>
      <description>&lt;p&gt;Tests hash-based SPA parameters (http://host/#/route?param=&amp;hellip;) for DOM XSS by mutating the hash in a dedicated attack tab and inspecting the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Specify postMessage targetOrigin</title>
      <link>/docs/alerts/220008-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-2/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Split Viewstate in Use</title>
      <link>/docs/alerts/10032-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-6/</guid>
      <description>&lt;p&gt;This website uses ASP.NET&amp;rsquo;s Viewstate and its value is split into several chunks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spring Actuator Information Leak</title>
      <link>/docs/alerts/40042/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40042/</guid>
      <description>&lt;p&gt;Spring Actuator for Health is enabled and may reveal sensitive information about this application. Spring Actuators can be used for real monitoring purposes, but should be used with caution as to not expose too much information about the application or the infrastructure running it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spring Boot actuator endpoint observed</title>
      <link>/docs/alerts/200019-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-3/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spring4Shell</title>
      <link>/docs/alerts/40045/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40045/</guid>
      <description>&lt;p&gt;The application appears to be vulnerable to CVE-2022-22965 (otherwise known as Spring4Shell) - remote code execution (RCE) via data binding.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection</title>
      <link>/docs/alerts/200000/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000/</guid>
      <description></description>
    </item>
    <item>
      <title>SQL Injection</title>
      <link>/docs/alerts/40018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40018/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Double Quote (after)</title>
      <link>/docs/alerts/200000-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-4/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Double Quote (before)</title>
      <link>/docs/alerts/200000-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-2/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Hypersonic SQL (Time Based)</title>
      <link>/docs/alerts/40020/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40020/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - MsSQL (Time Based)</title>
      <link>/docs/alerts/40027/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40027/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - MySQL (Time Based)</title>
      <link>/docs/alerts/40019/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40019/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Oracle (Time Based)</title>
      <link>/docs/alerts/40021/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40021/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - PostgreSQL (Time Based)</title>
      <link>/docs/alerts/40022/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40022/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Single Quote (after)</title>
      <link>/docs/alerts/200000-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-3/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - Single Quote (before)</title>
      <link>/docs/alerts/200000-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200000-1/</guid>
      <description>&lt;p&gt;A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - SQLite (Time Based)</title>
      <link>/docs/alerts/40024-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40024-1/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - SQLite (Time Based)</title>
      <link>/docs/alerts/40024-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40024-2/</guid>
      <description>&lt;p&gt;SQL injection may be possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection - SQLite (Time Based)</title>
      <link>/docs/alerts/40024/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40024/</guid>
      <description></description>
    </item>
    <item>
      <title>SSRF / webhook URL candidate parameter</title>
      <link>/docs/alerts/200015-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200015-2/</guid>
      <description>&lt;p&gt;Flags request parameters and JSON keys commonly associated with high-impact findings (open redirect, SSRF, IDOR, file/path traversal).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Storable and Cacheable Content</title>
      <link>/docs/alerts/10049-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10049-3/</guid>
      <description>&lt;p&gt;The response contents are storable by caching components such as proxy servers, and may be retrieved directly from the cache, rather than from the origin server by the caching servers, in response to similar requests from other users. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where &amp;ldquo;shared&amp;rdquo; caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Storable but Non-Cacheable Content</title>
      <link>/docs/alerts/10049-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10049-2/</guid>
      <description>&lt;p&gt;The response contents are storable by caching components such as proxy servers, but will not be retrieved directly from the cache, without validating the request upstream, in response to similar requests from other users.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Storage/referrer taint to execution sinks</title>
      <link>/docs/alerts/210018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210018/</guid>
      <description></description>
    </item>
    <item>
      <title>Strict-Transport-Security Defined via META (Non-compliant with Spec)</title>
      <link>/docs/alerts/10035-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-6/</guid>
      <description>&lt;p&gt;A HTTP Strict Transport Security (HSTS) META tag was found, defining HTTP Strict Transport Security (HSTS) via a META tag is explicitly not supported by the spec (RFC 6797).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security Disabled</title>
      <link>/docs/alerts/10035-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-2/</guid>
      <description>&lt;p&gt;A HTTP Strict Transport Security (HSTS) header was found, but it contains the directive max-age=0 which disables the control and instructs browsers to reset any previous HSTS related settings. See RFC 6797 for further details.&#xA;HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security Header</title>
      <link>/docs/alerts/10035/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035/</guid>
      <description></description>
    </item>
    <item>
      <title>Strict-Transport-Security Header Not Set</title>
      <link>/docs/alerts/10035-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-1/</guid>
      <description>&lt;p&gt;HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL). HSTS is an IETF standards track protocol and is specified in RFC 6797.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security Header on Plain HTTP Response</title>
      <link>/docs/alerts/10035-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-4/</guid>
      <description>&lt;p&gt;A HTTP Strict Transport Security (HSTS) header was found, but HSTS headers are ignored on plain (non-HTTPS) responses.&#xA;HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security Malformed Content (Non-compliant with Spec)</title>
      <link>/docs/alerts/10035-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-8/</guid>
      <description>&lt;p&gt;A HTTP Strict Transport Security (HSTS) header was found, but it contains some content that was not expected (perhaps curly quotes), the expectation is that the content be printable ASCII characters.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security Max-Age Malformed (Non-compliant with Spec)</title>
      <link>/docs/alerts/10035-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-7/</guid>
      <description>&lt;p&gt;A HTTP Strict Transport Security (HSTS) header was found, but it contains quotes preceding the max-age directive (the max-age value can be quoted, but the directive itself cannot be). See RFC 6797 for further details.&#xA;HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security Missing Max-Age (Non-compliant with Spec)</title>
      <link>/docs/alerts/10035-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-5/</guid>
      <description>&lt;p&gt;A HTTP Strict Transport Security (HSTS) header was found, but it is missing the max-age directive (or the directive is missing a value). See RFC 6797 for further details.&#xA;HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security Multiple Header Entries (Non-compliant with Spec)</title>
      <link>/docs/alerts/10035-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10035-3/</guid>
      <description>&lt;p&gt;HTTP Strict Transport Security (HSTS) headers were found, a response with multiple HSTS header entries is not compliant with the specification (RFC 6797) and only the first HSTS header will be processed others will be ignored by user agents or the HSTS policy may be incorrectly applied.&#xA;HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Strict-Transport-Security sent over HTTP (ineffective)</title>
      <link>/docs/alerts/200005-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-6/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Stripe publishable key exposed</title>
      <link>/docs/alerts/200011-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200011-7/</guid>
      <description>&lt;p&gt;Flags secret-like tokens and exposed configuration values in observed HTML/JS/JSON responses. These are recon leads; validate sensitivity before reporting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sub Resource Integrity Attribute Missing</title>
      <link>/docs/alerts/90003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90003/</guid>
      <description>&lt;p&gt;The integrity attribute is missing on a script or link tag served by an external server. The integrity tag prevents an attacker who have gained access to this server from injecting a malicious content.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation</title>
      <link>/docs/alerts/100044/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044/</guid>
      <description></description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Arithmetic Evaluation</title>
      <link>/docs/alerts/100044-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-2/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - EL Evaluation</title>
      <link>/docs/alerts/100044-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-5/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Expression Evaluation</title>
      <link>/docs/alerts/100044-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-3/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Quote Consumption</title>
      <link>/docs/alerts/100044-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-1/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Template Evaluation</title>
      <link>/docs/alerts/100044-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-4/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Unicode Byte Truncation</title>
      <link>/docs/alerts/100044-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-8/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Unicode Case Conversion</title>
      <link>/docs/alerts/100044-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-9/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Unicode Combining Diacritic</title>
      <link>/docs/alerts/100044-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-10/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - Unicode Normalisation</title>
      <link>/docs/alerts/100044-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-6/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suspicious Input Transformation - URL Decoding Error</title>
      <link>/docs/alerts/100044-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100044-7/</guid>
      <description>&lt;p&gt;The application performed a suspicious input transformation that may indicate a security vulnerability. The input was transformed in an unexpected way, suggesting potential issues with input validation, encoding/decoding, or expression evaluation. This could indicate vulnerabilities such as server-side template injection, expression language injection, unicode normalization issues, or other input processing flaws that may be exploitable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Swagger UI detected</title>
      <link>/docs/alerts/200012-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200012-1/</guid>
      <description>&lt;p&gt;Detects exposure of API documentation, specs, and interactive consoles observed in traffic.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Swagger UI Secret &amp; Vulnerability Detector</title>
      <link>/docs/alerts/100043/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100043/</guid>
      <description></description>
    </item>
    <item>
      <title>Swagger/OpenAPI path observed</title>
      <link>/docs/alerts/200019-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200019-4/</guid>
      <description>&lt;p&gt;Flags high-value endpoint patterns observed in traffic (admin panels, debug endpoints, consoles, and backup/config file paths).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted dangerous key used in prototype write</title>
      <link>/docs/alerts/210008-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210008-2/</guid>
      <description>&lt;p&gt;Tainted data reached a dangerous prototype key write.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted data compiled as AngularJS template</title>
      <link>/docs/alerts/220004-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-2/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted data passed to AngularJS $parse</title>
      <link>/docs/alerts/220004-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220004-1/</guid>
      <description>&lt;p&gt;Finds AngularJS code patterns where untrusted data is compiled or parsed as AngularJS expressions/templates, including $parse, $interpolate, $compile, interpolation delimiters and ng-* expression attributes.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted network destination URL</title>
      <link>/docs/alerts/220006-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220006-5/</guid>
      <description>&lt;p&gt;Detects client-side request destinations for beacon, EventSource, and Axios that can be influenced by attacker-controlled input.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted string executed via setInterval</title>
      <link>/docs/alerts/210011-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210011-2/</guid>
      <description>&lt;p&gt;Tainted string passed as the first argument to setInterval(), leading to repeated code execution.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted string executed via setTimeout</title>
      <link>/docs/alerts/210011-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210011-1/</guid>
      <description>&lt;p&gt;Tainted string passed as the first argument to setTimeout(), leading to code execution.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to element.href</title>
      <link>/docs/alerts/210014-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-1/</guid>
      <description>&lt;p&gt;Tainted URL assigned to an element href attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to element.src</title>
      <link>/docs/alerts/210014-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-2/</guid>
      <description>&lt;p&gt;Tainted URL assigned to a non-script/iframe/src element src attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to form action</title>
      <link>/docs/alerts/210014-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-3/</guid>
      <description>&lt;p&gt;Tainted URL assigned to a form action attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted URL assigned to formAction</title>
      <link>/docs/alerts/210014-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210014-4/</guid>
      <description>&lt;p&gt;Tainted URL assigned to a formAction attribute.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tainted worker or script loader URL</title>
      <link>/docs/alerts/220007-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220007-8/</guid>
      <description>&lt;p&gt;Detects dynamic script, worker, and service-worker loader endpoints that can be influenced by attacker-controlled client-side data.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tech Detection Passive Scanner</title>
      <link>/docs/alerts/10004/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10004/</guid>
      <description>&lt;p&gt;The following &amp;ldquo;Widgets&amp;rdquo; technology was identified: Example Software.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Telerik UI for ASP.NET AJAX Cryptographic Weakness (CVE-2017-9248)</title>
      <link>/docs/alerts/100021/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100021/</guid>
      <description>&lt;p&gt;A request has been made that appears to conform to poor cryptography used by Telerik UI for ASP.NET AJAX prior to v2017.2.621.&#xA;An attacker could manipulate the value of the dp parameter to possibly learn the machine key and upload arbitrary files, which could then lead to the compromise of ASP.NET ViewStates and arbitrary code execution respectively.&#xA;CVE-2017-9248 has a CVSSv3 score of 9.8.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Template injection (taint flow)</title>
      <link>/docs/alerts/220005-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-4/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Template output injected into DOM</title>
      <link>/docs/alerts/220005-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220005-2/</guid>
      <description>&lt;p&gt;Detects dynamic client-side template compilation/rendering where attacker-controlled templates or outputs are injected into the DOM.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>template.innerHTML with dynamic content</title>
      <link>/docs/alerts/220000-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220000-5/</guid>
      <description>&lt;p&gt;Detects cases where untrusted data from the DOM (URL, element values, storage, messages, etc.) flows into HTML/JS execution sinks (e.g., innerHTML, outerHTML, document.write, string-based setTimeout, insertAdjacentHTML) without proper sanitization or encoding \u2014 enabling DOM-based cross-site scripting.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Text4shell (CVE-2022-42889)</title>
      <link>/docs/alerts/40047/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40047/</guid>
      <description>&lt;p&gt;Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults.Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.The application has been shown to initial contact with remote servers via variable interpolation and may well be vulnerable to Remote Code Execution (RCE).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Timer-based JS execution sinks</title>
      <link>/docs/alerts/210011/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210011/</guid>
      <description></description>
    </item>
    <item>
      <title>Timestamp Disclosure - Unix</title>
      <link>/docs/alerts/10096/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10096/</guid>
      <description>&lt;p&gt;A timestamp was disclosed by the application/web server. - Unix&lt;/p&gt;</description>
    </item>
    <item>
      <title>Trace.axd Information Leak</title>
      <link>/docs/alerts/40029/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40029/</guid>
      <description>&lt;p&gt;The ASP.NET Trace Viewer (trace.axd) was found to be available. This component can leak a significant amount of valuable information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Unexpected Content-Type was returned</title>
      <link>/docs/alerts/100001/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100001/</guid>
      <description>&lt;p&gt;A Content-Type of application/test was returned by the server.&#xA;This is not one of the types expected to be returned by an API.&#xA;Raised by the &amp;lsquo;Alert on Unexpected Content Types&amp;rsquo; script&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted DOM data into createHTMLDocument</title>
      <link>/docs/alerts/220010-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220010-2/</guid>
      <description>&lt;p&gt;Detects untrusted DOM data being written into form metadata (formAction/target/method/value/placeholder), inline style surfaces (style/cssText/background*), document.title, history state, or createHTMLDocument — mutations that influence UI/navigation state without covering classic href/src/action sinks already handled elsewhere.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted DOM data into navigation-adjacent sinks</title>
      <link>/docs/alerts/220010-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220010-1/</guid>
      <description>&lt;p&gt;Detects untrusted DOM data being written into form metadata (formAction/target/method/value/placeholder), inline style surfaces (style/cssText/background*), document.title, history state, or createHTMLDocument — mutations that influence UI/navigation state without covering classic href/src/action sinks already handled elsewhere.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted DOM data into UI mutation sinks</title>
      <link>/docs/alerts/220010-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220010-3/</guid>
      <description>&lt;p&gt;Detects untrusted DOM data being written into form metadata (formAction/target/method/value/placeholder), inline style surfaces (style/cssText/background*), document.title, history state, or createHTMLDocument — mutations that influence UI/navigation state without covering classic href/src/action sinks already handled elsewhere.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Upload Form Discovered</title>
      <link>/docs/alerts/100022/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100022/</guid>
      <description>&lt;p&gt;The presence of a file upload form can lead to various security vulnerabilities, such as uploading malicious files or overwriting existing files, if proper validation and restrictions are not implemented. This can result in unauthorized code execution, data breaches, or denial of service attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Use of SAML</title>
      <link>/docs/alerts/10070/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10070/</guid>
      <description>&lt;p&gt;&lt;em&gt;Unavailable&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>User Agent Fuzzer</title>
      <link>/docs/alerts/10104/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10104/</guid>
      <description>&lt;p&gt;Check for differences in response based on fuzzed User Agent (eg. mobile sites, access as a Search Engine Crawler). Compares the response statuscode and the hashcode of the response body with the original response.&lt;/p&gt;</description>
    </item>
    <item>
      <title>User Controllable Charset</title>
      <link>/docs/alerts/10030/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10030/</guid>
      <description>&lt;p&gt;This check looks at user-supplied input in query string parameters and POST data to identify where Content-Type or meta tag charset declarations might be user-controlled. Such charset declarations should always be declared by the application. If an attacker can control the response charset, they could manipulate the HTML to perform XSS or other attacks. For example, an attacker controlling the &lt;!-- raw HTML omitted --&gt; element charset value is able to declare UTF-7 and is also able to include enough user-controlled payload early in the HTML document to have it interpreted as UTF-7. By encoding their payload with UTF-7 the attacker is able to bypass any server-side XSS protections and embed script in the page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>User Controllable HTML Element Attribute (Potential XSS)</title>
      <link>/docs/alerts/10031/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10031/</guid>
      <description>&lt;p&gt;This check looks at user-supplied input in query string parameters and POST data to identify where certain HTML attribute values might be controlled. This provides hot-spot detection for XSS (cross-site scripting) that will require further review by a security analyst to determine exploitability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>User Controllable JavaScript Event (XSS)</title>
      <link>/docs/alerts/10043/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10043/</guid>
      <description>&lt;p&gt;This check looks at user-supplied input in query string parameters and POST data to identify where certain HTML attribute values might be controlled. This provides hot-spot detection for XSS (cross-site scripting) that will require further review by a security analyst to determine exploitability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Username Hash Found</title>
      <link>/docs/alerts/10057/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10057/</guid>
      <description>&lt;p&gt;A hash of a username (admin) was found in the response. This may indicate that the application is subject to an Insecure Direct Object Reference (IDOR) vulnerability. Manual testing will be required to see if this discovery can be abused.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Username Hash Found in WebSocket message</title>
      <link>/docs/alerts/110007/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/110007/</guid>
      <description>&lt;p&gt;A Example hash of {Example / context: Example} was found in incoming WebSocket message. This may indicate that the application is subject to an Insecure Direct Object Reference (IDOR) vulnerability. Manual testing will be required to see if this discovery can be abused.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Verification Request Identified</title>
      <link>/docs/alerts/10113/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10113/</guid>
      <description>&lt;p&gt;The given request has been identified as a good candidate for authentication verification. If the request is in a context which has a Verification Strategy set to &amp;ldquo;Poll&amp;rdquo; but where the URL is empty then this rule will fill in the correct values.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Viewstate</title>
      <link>/docs/alerts/10032/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032/</guid>
      <description></description>
    </item>
    <item>
      <title>Viewstate without MAC Signature (Sure)</title>
      <link>/docs/alerts/10032-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-5/</guid>
      <description>&lt;p&gt;This website uses ASP.NET&amp;rsquo;s Viewstate but without any MAC.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Viewstate without MAC Signature (Unsure)</title>
      <link>/docs/alerts/10032-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10032-4/</guid>
      <description>&lt;p&gt;This website uses ASP.NET&amp;rsquo;s Viewstate but maybe without any MAC.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerable JS Library</title>
      <link>/docs/alerts/10003/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10003/</guid>
      <description>&lt;p&gt;The identified library appears to be vulnerable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerable Swagger UI Version Detected</title>
      <link>/docs/alerts/100043-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/100043-1/</guid>
      <description>&lt;p&gt;This Swagger UI version is known to contain vulnerabilities. Exploitation may allow unauthorized access, XSS, or token theft.&lt;/p&gt;&#xA;&lt;p&gt;Affected versions:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Swagger UI v2 &amp;lt; 2.2.10&lt;/li&gt;&#xA;&lt;li&gt;Swagger UI v3 &amp;lt; 3.24.3&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Weak Authentication Method</title>
      <link>/docs/alerts/10105-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10105-2/</guid>
      <description>&lt;p&gt;HTTP basic or digest authentication has been used over an unsecured connection. The credentials can be read and then reused by someone with access to the network.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Weak Authentication Method</title>
      <link>/docs/alerts/10105/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10105/</guid>
      <description></description>
    </item>
    <item>
      <title>Web Cache Deception</title>
      <link>/docs/alerts/40039/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40039/</guid>
      <description>&lt;p&gt;Web cache deception may be possible. It may be possible for unauthorised user to view sensitive data on this page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web Message Handling</title>
      <link>/docs/alerts/220008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008/</guid>
      <description></description>
    </item>
    <item>
      <title>Web Message Injection (taint flow)</title>
      <link>/docs/alerts/220008-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-9/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webpack dev-server / hot reload artifacts</title>
      <link>/docs/alerts/200009-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200009-3/</guid>
      <description>&lt;p&gt;Detects source map references and common debug artifacts in observed HTML/JS responses. These are high-value recon leads for code disclosure and hidden endpoints.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wildcard reply from message handler</title>
      <link>/docs/alerts/220008-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/220008-8/</guid>
      <description>&lt;p&gt;Detects unsafe postMessage usage and message event handling issues (missing origin validation, wildcard targetOrigin, tainted data flowing into DOM/code sinks).&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK SAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>window.open redirect from tainted source</title>
      <link>/docs/alerts/210019-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210019-4/</guid>
      <description>&lt;p&gt;Tainted value passed to window.open.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK IAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>window.postMessage misuse</title>
      <link>/docs/alerts/210010/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/210010/</guid>
      <description></description>
    </item>
    <item>
      <title>ws:// from HTTPS context</title>
      <link>/docs/alerts/200008/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200008/</guid>
      <description>&lt;p&gt;Looks for common WebSocket endpoints and insecure patterns such as ws:// from HTTPS pages.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>WSDL File Detection</title>
      <link>/docs/alerts/90030/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90030/</guid>
      <description>&lt;p&gt;A WSDL File has been detected.&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-AspNet-Version Response Header</title>
      <link>/docs/alerts/10061/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10061/</guid>
      <description>&lt;p&gt;Server leaks information via &amp;ldquo;X-AspNet-Version&amp;rdquo;/&amp;ldquo;X-AspNetMvc-Version&amp;rdquo; HTTP response header field(s).&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Backend-Server Header Information Leak</title>
      <link>/docs/alerts/10039/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10039/</guid>
      <description>&lt;p&gt;The server is leaking information pertaining to backend systems (such as hostnames or IP addresses). Armed with this information an attacker may be able to attack other systems or more directly/efficiently attack those systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-ChromeLogger-Data (XCOLD) Header Information Leak</title>
      <link>/docs/alerts/10052/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10052/</guid>
      <description>&lt;p&gt;The server is leaking information through the X-ChromeLogger-Data (or X-ChromePhp-Data) response header. The content of such headers can be customized by the developer, however it is not uncommon to find: server file system locations, vhost declarations, etc.&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Content-Type-Options Header Missing</title>
      <link>/docs/alerts/10021/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10021/</guid>
      <description>&lt;p&gt;The Anti-MIME-Sniffing header X-Content-Type-Options was not set to &amp;rsquo;nosniff&amp;rsquo;. This allows older versions of Internet Explorer and Chrome to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the declared content type. Current (early 2014) and legacy versions of Firefox will use the declared content type (if one is set), rather than performing MIME-sniffing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Debug-Token Information Leak</title>
      <link>/docs/alerts/10056/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10056/</guid>
      <description>&lt;p&gt;The response contained an X-Debug-Token or X-Debug-Token-Link header. This indicates that Symfony&amp;rsquo;s Profiler may be in use and exposing sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Frame-Options Defined via META (Non-compliant with Spec)</title>
      <link>/docs/alerts/10020-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10020-3/</guid>
      <description>&lt;p&gt;An X-Frame-Options (XFO) META tag was found, defining XFO via a META tag is explicitly not supported by the spec (RFC 7034).&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Frame-Options Setting Malformed</title>
      <link>/docs/alerts/10020-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10020-4/</guid>
      <description>&lt;p&gt;An X-Frame-Options header was present in the response but the value was not correctly set.&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-Powered-By header or equivalent present</title>
      <link>/docs/alerts/200005-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-8/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>X-XSS-Protection header is a legacy directive</title>
      <link>/docs/alerts/200005-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200005-11/</guid>
      <description>&lt;p&gt;The OWASP Secure Headers Project describes HTTP response headers that your application can use to increase the security of your application. Once set, these HTTP response headers can restrict modern browsers from running into easily preventable vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>XML External Entity Attack</title>
      <link>/docs/alerts/90023/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90023/</guid>
      <description>&lt;p&gt;This technique takes advantage of a feature of XML to build documents dynamically at the time of processing. An XML message can either provide data explicitly or by pointing to an URI where the data exists. In the attack technique, external entities may replace the entity value with malicious data, alternate referrals or may compromise the security of the data the server/XML application has access to.&#xA;Attackers may also use External Entities to have the web services server download malicious code or content to the server for use in secondary or follow on attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XPath Injection</title>
      <link>/docs/alerts/90021/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90021/</guid>
      <description>&lt;p&gt;XPath Injection is an attack technique used to exploit applications that construct XPath (XML Path Language) queries from user-supplied input to query or navigate XML documents. It can be used directly by an application to query an XML document, as part of a larger operation such as applying an XSLT transformation to an XML document, or applying an XQuery to an XML document. The syntax of XPath bears some resemblance to an SQL query, and indeed, it is possible to form SQL-like queries on an XML document using XPath.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSLT Injection</title>
      <link>/docs/alerts/90017/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/90017/</guid>
      <description>&lt;p&gt;Injection using XSL transformations may be possible, and may allow an attacker to read system information, read and write files, or execute arbitrary code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - attribute context img onerror</title>
      <link>/docs/alerts/200002-6/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-6/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - attribute-name event injection</title>
      <link>/docs/alerts/200002-17/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-17/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - double-quoted attribute event injection</title>
      <link>/docs/alerts/200002-14/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-14/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Img onerror</title>
      <link>/docs/alerts/200002-4/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-4/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Img onerror</title>
      <link>/docs/alerts/200002-5/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-5/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS block comment break-out</title>
      <link>/docs/alerts/200002-13/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-13/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS expression replacement</title>
      <link>/docs/alerts/200002-10/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-10/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS single-quoted string break-out</title>
      <link>/docs/alerts/200002-11/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-11/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS slash/regex literal break-out</title>
      <link>/docs/alerts/200002-12/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-12/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS string break-out</title>
      <link>/docs/alerts/200002-8/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-8/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - JS template literal break-out</title>
      <link>/docs/alerts/200002-9/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-9/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Script tag after noscript tag</title>
      <link>/docs/alerts/200002-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-2/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - single-quoted attribute event injection</title>
      <link>/docs/alerts/200002-15/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-15/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - SVG onload polyglot</title>
      <link>/docs/alerts/200002-7/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-7/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Svg tag with animation event</title>
      <link>/docs/alerts/200002-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-3/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - tag-name SVG onload injection</title>
      <link>/docs/alerts/200002-18/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-18/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - Unfiltered &lt;script&gt; tag</title>
      <link>/docs/alerts/200002-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-1/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS - unquoted attribute event injection</title>
      <link>/docs/alerts/200002-16/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200002-16/</guid>
      <description>&lt;p&gt;Reflected Cross-site Scripting (XSS) is another name for non-persistent XSS, where the attack doesn&amp;rsquo;t load with the vulnerable web application but is originated by the victim loading the offending URI. In this article we will see some ways to test a web application for this kind of vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP is Out of Date</title>
      <link>/docs/alerts/10116/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10116/</guid>
      <description>&lt;p&gt;The version of ZAP you are using to test your app is out of date and is no longer being updated.&#xA;The risk level is set based on how out of date your ZAP version is.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
