-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
-
Site: http://testphp.vulnweb.com
New Alerts- Cross Site Scripting (DOM Based) [40026] total: 16:
- [http://testphp.vulnweb.com/artists.php?name=abc#
](http://testphp.vulnweb.com/artists.php?name=abc#
) - [http://testphp.vulnweb.com/cart.php#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](http://testphp.vulnweb.com/cart.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e) - [http://testphp.vulnweb.com/categories.php#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](http://testphp.vulnweb.com/categories.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e) - [http://testphp.vulnweb.com/disclaimer.php#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](http://testphp.vulnweb.com/disclaimer.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e) - [http://testphp.vulnweb.com/guestbook.php#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](http://testphp.vulnweb.com/guestbook.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e) - ..
- [http://testphp.vulnweb.com/artists.php?name=abc#
- Cross Site Scripting (Reflected) [40012] total: 14:
- http://testphp.vulnweb.com/hpp/?pp=%22%3E%3CscrIpt%3Ealert%281%29%3B%3C%2FscRipt%3E
- http://testphp.vulnweb.com/hpp/params.php?p=%3CscrIpt%3Ealert%281%29%3B%3C%2FscRipt%3E&pp=12
- http://testphp.vulnweb.com/hpp/params.php?p=valid&pp=%3CscrIpt%3Ealert%281%29%3B%3C%2FscRipt%3E
- http://testphp.vulnweb.com/listproducts.php?artist=%3Cimg+src%3Dx+onerror%3Dprompt%28%29%3E
- http://testphp.vulnweb.com/listproducts.php?cat=%3Cimg+src%3Dx+onerror%3Dprompt%28%29%3E
- ..
- Cross-Domain Misconfiguration - Adobe - Read [20016] total: 1:
- NoSQL Injection - MongoDB [40033] total: 4:
- SQL Injection [40018] total: 7:
- Source Code Disclosure - File Inclusion [43] total: 4:
- .htaccess Information Leak [40032] total: 7:
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/.htaccess
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/BuyProduct-1/.htaccess
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/BuyProduct-2/.htaccess
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/BuyProduct-3/.htaccess
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/.htaccess
- ..
- Absence of Anti-CSRF Tokens [10202] total: 10:
- Anti-CSRF Tokens Check [20012] total: 23:
- Backup File Disclosure [10095] total: 14:
- http://testphp.vulnweb.com/index.bak
- http://testphp.vulnweb.com/index.zip
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/RateProduct-1%20-%20Copy%20(2).html
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/RateProduct-1%20-%20Copy%20(3).html
- http://testphp.vulnweb.com/Mod_Rewrite_Shop/RateProduct-1%20-%20Copy.html
- ..
- Content Security Policy (CSP) Header Not Set [10038] total: 11:
- HTTP Only Site [10106] total: 1:
- Missing Anti-clickjacking Header [10020] total: 11:
- XSLT Injection [90017] total: 2:
- In Page Banner Information Leak [10009] total: 3:
- Permissions Policy Header Not Set [10063] total: 11:
- Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s) [10037] total: 11:
- Server Leaks Version Information via "Server" HTTP Response Header Field [10036] total: 11:
- X-Content-Type-Options Header Missing [10021] total: 12:
- Authentication Request Identified [10111] total: 1:
- Base64 Disclosure [10094] total: 11:
- Charset Mismatch (Header Versus Meta Content-Type Charset) [90011] total: 11:
- GET for POST [10058] total: 1:
- Information Disclosure - Suspicious Comments [10027] total: 1:
- Modern Web Application [10109] total: 9:
- Non-Storable Content [10049] total: 1:
- Sec-Fetch-Dest Header is Missing [90005] total: 3:
- Sec-Fetch-Mode Header is Missing [90005] total: 3:
- Sec-Fetch-Site Header is Missing [90005] total: 3:
- Sec-Fetch-User Header is Missing [90005] total: 3:
- Storable and Cacheable Content [10049] total: 11:
- User Agent Fuzzer [10104] total: 223:
- User Controllable HTML Element Attribute (Potential XSS) [10031] total: 3:
- Cross Site Scripting (DOM Based) [40026] total: 16:
View the following link to download the report.
RunnerID:7212426648
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels