Generated on Wed, 4 May 2022 16:30:32

Summary of Alerts

Risk Level Number of Alerts
High
0
Medium
6
Low
5
Informational
7

Passing Rules

Name Rule Type Threshold Strength
Session ID in URL Rewrite Passive MEDIUM -
Cookie without SameSite Attribute Passive MEDIUM -
X-Debug-Token Information Leak Passive MEDIUM -
Username Hash Found Passive MEDIUM -
X-AspNet-Version Response Header Passive MEDIUM -
Insecure JSF ViewState Passive MEDIUM -
Sub Resource Integrity Attribute Missing Passive MEDIUM -
Stats Passive Scan Rule Passive MEDIUM -
Java Serialization Object Passive MEDIUM -
Insufficient Site Isolation Against Spectre Vulnerability Passive MEDIUM -
Use of SAML Passive MEDIUM -
In Page Banner Information Leak Passive MEDIUM -
Charset Mismatch Passive MEDIUM -
Cookie No HttpOnly Flag Passive MEDIUM -
Cookie Without Secure Flag Passive MEDIUM -
Incomplete or No Cache-control Header Set Passive MEDIUM -
Example Passive Scan Rule: Denial of Service Passive MEDIUM -
Cross-Domain JavaScript Source File Inclusion Passive MEDIUM -
An example passive scan rule which loads data from a file. Passive MEDIUM -
Content-Type Header Missing Passive MEDIUM -
Anti-clickjacking Header Passive MEDIUM -
X-Content-Type-Options Header Missing Passive MEDIUM -
Application Error Disclosure Passive MEDIUM -
Information Disclosure - Debug Error Messages Passive MEDIUM -
Information Disclosure - Sensitive Information in URL Passive MEDIUM -
Information Disclosure - Sensitive Information in HTTP Referrer Header Passive MEDIUM -
WSDL File Detection Passive MEDIUM -
Loosely Scoped Cookie Passive MEDIUM -
Viewstate Passive MEDIUM -
Cross-Domain Misconfiguration Passive MEDIUM -
Source Code Disclosure Passive MEDIUM -
Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s) Passive MEDIUM -
Secure Pages Include Mixed Content Passive MEDIUM -
Weak Authentication Method Passive MEDIUM -

Sites

https://optimizationguide-pa.googleapis.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

http://192.168.2.47

HTTP Response Code Number of Responses
404 Not Found
2
200 OK
36
Authentication Statistics Number of Responses
!reports.report.stats.auth.manual.state.unknown!
1
!reports.report.stats.auth.proxy.state.unknown!
3
!reports.report.stats.auth.spider.state.notsuccess!
2
!reports.report.stats.auth.spider.state.nothtml!
31
!reports.report.stats.auth.spider.state.unknown!
1
Parameter Name Type Flags Times Used # Values

https://accounts.google.com

HTTP Response Code Number of Responses

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

Alert Detail

Medium
CSP: Wildcard Directive
Description
The following directives either allow wildcard sources (or ancestors), are not defined, or are overly broadly defined:

connects-src, frame-ancestors, manifest-src, prefetch-src, form-action

The directive(s): frame-ancestors, form-action are among the directives that do not fallback to default-src, missing/excluding them is the same as allowing anything.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/robots.txt
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 299 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/sitemap.xml
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 300 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 6
Solution
Ensure that your web server, application server, load balancer, etc. is properly configured to set the Content-Security-Policy header.
Reference http://www.w3.org/TR/CSP2/
http://www.w3.org/TR/CSP/
http://caniuse.com/#search=content+security+policy
http://content-security-policy.com/
https://github.com/shapesecurity/salvation
https://developers.google.com/web/fundamentals/security/csp#policy_applies_to_a_wide_variety_of_resources
Tags OWASP_2021_A05
OWASP_2017_A06
CWE Id 693
WASC Id 15
Plugin Id 10055
Medium
CSP: script-src unsafe-inline
Description
script-src includes unsafe-inline.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/robots.txt
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 299 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/sitemap.xml
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 300 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 6
Solution
Ensure that your web server, application server, load balancer, etc. is properly configured to set the Content-Security-Policy header.
Reference http://www.w3.org/TR/CSP2/
http://www.w3.org/TR/CSP/
http://caniuse.com/#search=content+security+policy
http://content-security-policy.com/
https://github.com/shapesecurity/salvation
https://developers.google.com/web/fundamentals/security/csp#policy_applies_to_a_wide_variety_of_resources
Tags OWASP_2021_A05
OWASP_2017_A06
CWE Id 693
WASC Id 15
Plugin Id 10055
Medium
CSP: style-src unsafe-inline
Description
style-src includes unsafe-inline.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/robots.txt
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 299 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/sitemap.xml
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 300 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://yui.yahooapis.com http://ajax.googleapis.com https://ajax.googleapis.com; object-src 'self'; style-src 'self' data: 'unsafe-inline' https://maps.googleapis.com https://maps.gstatic.com https://fonts.googleapis.com https://www.gstatic.com https://maxcdn.bootstrapcdn.com/; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.gstatic.com http://icant.co.uk http://yui.yahooapis.com http://o.aolcdn.com http://maps.google.com; media-src 'self'; frame-src 'self'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 6
Solution
Ensure that your web server, application server, load balancer, etc. is properly configured to set the Content-Security-Policy header.
Reference http://www.w3.org/TR/CSP2/
http://www.w3.org/TR/CSP/
http://caniuse.com/#search=content+security+policy
http://content-security-policy.com/
https://github.com/shapesecurity/salvation
https://developers.google.com/web/fundamentals/security/csp#policy_applies_to_a_wide_variety_of_resources
Tags OWASP_2021_A05
OWASP_2017_A06
CWE Id 693
WASC Id 15
Plugin Id 10055
Medium
Potential Relative Path Overwrite - RPO(beta script)
Description
Potential RPO (Relative Path Overwrite) found
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 4
Solution
Make sure all style sheets are refered by full paths rather than relative paths.
Reference
Tags
CWE Id
WASC Id
Plugin Id 50001
Medium
Private IP address in Body(script)
Description
A private IP such as 10.x.x.x, 172.x.x.x, 192.168.x.x or IPV6 fe00:: has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
Instances 2
Solution
Remove the private IP address from the HTTP response body. For comments, use JSP/ASP comment instead of HTML/JavaScript comment which can be seen by client browsers.
Reference
Tags
CWE Id
WASC Id
Plugin Id 50001
Medium
Vulnerable JS Library
Description
The identified library jquery, version 1.10.2 is vulnerable.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence jquery-1.10.2.min.js
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-ui-1.10.4.custom.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence /*! jQuery UI - v1.10.4
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 228,560 bytes.
Instances 2
Solution
Please upgrade to the latest version of jquery.
Reference https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
http://research.insecurelabs.org/jquery/test/
https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/
https://nvd.nist.gov/vuln/detail/CVE-2019-11358
https://nvd.nist.gov/vuln/detail/CVE-2015-9251
https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b
https://bugs.jquery.com/ticket/11974
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
Tags OWASP_2017_A09
OWASP_2021_A06
CWE Id 829
WASC Id
Plugin Id 10003
Low
Absence of Anti-CSRF Tokens
Description
No Anti-CSRF tokens were found in a HTML submission form.

A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.

CSRF attacks are effective in a number of situations, including:

* The victim has an active session on the target site.

* The victim is authenticated via HTTP auth on the target site.

* The victim is on the same local network as the target site.

CSRF has primarily been used to perform an action against a target site using the victim's privileges, but recent techniques have been discovered to disclose information by gaining access to the response. The risk of information disclosure is dramatically increased when the target site is vulnerable to XSS, because XSS can be used as a platform for CSRF, allowing the attack to operate within the bounds of the same-origin policy.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence <form name='myform' id='myform' method='post'>
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence <form method='POST' name='myform' id='myform' target='_self' action="" >
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence <form name="myform" id="myform" action="" method="POST">
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence <form method='POST' name='myform' id='myform' target='_self' action="" >
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 4
Solution
Phase: Architecture and Design

Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

For example, use anti-CSRF packages such as the OWASP CSRFGuard.

Phase: Implementation

Ensure that your application is free of cross-site scripting issues, because most CSRF defenses can be bypassed using attacker-controlled script.

Phase: Architecture and Design

Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330).

Note that this can be bypassed using XSS.

Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.

Note that this can be bypassed using XSS.

Use the ESAPI Session Management control.

This control includes a component for CSRF.

Do not use the GET method for any request that triggers a state change.

Phase: Implementation

Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.
Reference http://projects.webappsec.org/Cross-Site-Request-Forgery
http://cwe.mitre.org/data/definitions/352.html
Tags OWASP_2021_A01
WSTG-v42-SESS-05
OWASP_2017_A05
CWE Id 352
WASC Id 9
Plugin Id 10202
Low
Dangerous JS Functions
Description
A dangerous JS function seems to be in use that would leave the site vulnerable.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence eval
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
Instances 1
Solution
See the references for security advice on the use of these functions.
Reference https://angular.io/guide/security
Tags WSTG-v42-CLNT-02
OWASP_2021_A04
CWE Id 749
WASC Id
Plugin Id 10110
Low
Permissions Policy Header Not Set
Description
Permissions Policy Header is an added layer of security that helps to restrict from unauthorized access or usage of browser/client features by web resources. This policy ensures the user privacy by limiting or specifying the features of the browsers can be used by the web resources. Permissions Policy provides a set of standard HTTP headers that allow website owners to limit which features of browsers can be used by the page such as camera, microphone, location, full screen etc.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/greaterdate_function.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 472 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 2,104 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/jquery.blockUI.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 20,322 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/lst_freeze_table/lst_freeze_table.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 485 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 9,219 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/sha1.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 456 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 3,459 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/shadedborder.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 464 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 9,626 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/alertify.min.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 33,298 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-ui-1.10.4.custom.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 228,560 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/jquery.cookie.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 465 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 1,940 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 34,511 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/spinner/jquery.ui.spinner.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 12,529 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/splitter/js/jquery.splitter-0.14.0.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 11,897 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/robots.txt
Method GET
Parameter
Attack
Evidence
Request Header - size: 299 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/sitemap.xml
Method GET
Parameter
Attack
Evidence
Request Header - size: 300 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 18
Solution
Ensure that your web server, application server, load balancer, etc. is configured to set the Permissions-Policy header.
Reference https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Feature-Policy
https://developers.google.com/web/updates/2018/06/feature-policy
https://scotthelme.co.uk/a-new-security-header-feature-policy/
https://w3c.github.io/webappsec-feature-policy/
https://www.smashingmagazine.com/2018/12/feature-policy/
Tags OWASP_2021_A01
OWASP_2017_A05
CWE Id 693
WASC Id 15
Plugin Id 10063
Low
Private IP Disclosure
Description
A private IP (such as 10.x.x.x, 172.x.x.x, 192.168.x.x) or an Amazon EC2 private hostname (for example, ip-10-0-56-78) has been found in the HTTP response body. This information might be helpful for further attacks targeting internal systems.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence 10.0.0.10
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
Instances 1
Solution
Remove the private IP address from the HTTP response body. For comments, use JSP/ASP/PHP comment instead of HTML/JavaScript comment which can be seen by client browsers.
Reference https://tools.ietf.org/html/rfc1918
Tags OWASP_2021_A01
OWASP_2017_A03
CWE Id 200
WASC Id 13
Plugin Id 2
Low
Timestamp Disclosure - Unix
Description
A timestamp was disclosed by the application/web server - Unix
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence 23070303
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence 23212121
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence 23222222
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence 23363636
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence 23454545
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence 23999999
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence 20030331
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence 20110929
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-ui-1.10.4.custom.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence 0123456789
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 228,560 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence 20180420
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence 20190311
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000000015
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000000488
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000001230
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000001289
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000001395
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000001506
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000001620
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000001836
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000002124
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence 0000006455
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/main.css?v=20220209161358
Method GET
Parameter
Attack
Evidence 20190215
Request Header - size: 458 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 5,269 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/main.css?v=20220209161358
Method GET
Parameter
Attack
Evidence 20190222
Request Header - size: 458 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 5,269 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/main.css?v=20220209161358
Method GET
Parameter
Attack
Evidence 20190226
Request Header - size: 458 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 5,269 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence 10000000
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence 20180420
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence 20180820
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence 20190130
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence 20190301
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence 20190606
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence 10000000
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence 20180420
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence 20180820
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence 20180831
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence 20190301
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence 20190606
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 36
Solution
Manually confirm that the timestamp data is not sensitive, and that the data cannot be aggregated to disclose exploitable patterns.
Reference http://projects.webappsec.org/w/page/13246936/Information%20Leakage
Tags OWASP_2021_A01
OWASP_2017_A03
CWE Id 200
WASC Id 13
Plugin Id 10096
Informational
An upload form appeared! (script)
Description
An upload form exists. This isn't an issue, but it could be a lot of fun! Go check it out!.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/pis.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 457 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,760 bytes.
Instances 1
Solution
This isn't an issue, but it could be a lot of fun!
Reference
Tags
CWE Id
WASC Id
Plugin Id 50001
Informational
Base64 Disclosure
Description
Base64 encoded data was disclosed by the application/web server. Note: in the interests of performance not all base64 strings in the response were analyzed individually, the entire response should be looked at by the analyst/security team/developer(s).
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/css/alertify.min.css?v=20220209161346
Method GET
Parameter
Attack
Evidence iVBORw0KGgoAAAANSUhEUgAAAAoAAAAKCAYAAACNMs+9AAAABHNCSVQICAgIfAhkiAAAAAlwSFlzAAALEgAACxIB0t1+/AAAABZ0RVh0Q3JlYXRpb24gVGltZQAwNy8xMy8xNOrZqugAAAAcdEVYdFNvZnR3YXJlAEFkb2JlIEZpcmV3b3JrcyBDUzbovLKMAAAAh0lEQVQYlY2QsQ0EIQwEB9cBAR1CJUaI/gigDnwR6NBL/7/xWLNrZ2b8EwGotVpr7eOitWa1VjugiNB7R1UPrKrWe0dEAHBbXUqxMQbeewDmnHjvyTm7C3zDwAUd9c63YQdUVdu6EAJzzquz7HXvTiklt+H9DQFYaxFjvDqllFyMkbXWvfpXHjJrWFgdBq/hAAAAAElFTkSuQmCC
Request Header - size: 471 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 19,192 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence org/TR/2011/REC-css3-selectors-20110929/
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
Instances 3
Solution
Manually confirm that the Base64 data does not leak sensitive information, and that the data cannot be aggregated/used to exploit other vulnerabilities.
Reference http://projects.webappsec.org/w/page/13246936/Information%20Leakage
Tags OWASP_2021_A04
OWASP_2017_A03
CWE Id 200
WASC Id 13
Plugin Id 10094
Informational
Email addresses (script)
Description
Email addresses were found
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/alertify.min.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 33,298 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/css/alertify.min.css?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 471 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 19,192 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/css/themes/bootstrap.min.css?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,243 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/style.fluid.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 465 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,128 bytes.
Response Body - size: 467 bytes.
Instances 4
Solution
Remove emails that are not public
Reference
Tags
CWE Id
WASC Id
Plugin Id 50001
Informational
Information Disclosure - Suspicious Comments
Description
The response appears to contain suspicious comments which may help an attacker. Note: Matches made within script blocks or files are against the entire content not only comments.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/jquery.blockUI.js?v=20220209161346
Method GET
Parameter
Attack
Evidence from
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 20,322 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/jquery.blockUI.js?v=20220209161346
Method GET
Parameter
Attack
Evidence later
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 20,322 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/jquery.blockUI.js?v=20220209161346
Method GET
Parameter
Attack
Evidence where
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 20,322 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/alertify.min.js?v=20220209161346
Method GET
Parameter
Attack
Evidence Db
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 33,298 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence bug
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence bugs
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence from
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence later
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence query
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence select
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence user
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence username
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence where
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-ui-1.10.4.custom.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence select
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 228,560 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.js?v=20220209161352
Method GET
Parameter
Attack
Evidence from
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 34,511 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.js?v=20220209161352
Method GET
Parameter
Attack
Evidence select
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 34,511 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.js?v=20220209161352
Method GET
Parameter
Attack
Evidence TODO
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 34,511 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.js?v=20220209161352
Method GET
Parameter
Attack
Evidence user
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 34,511 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.js?v=20220209161352
Method GET
Parameter
Attack
Evidence XXX
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 34,511 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/spinner/jquery.ui.spinner.js?v=20220209161352
Method GET
Parameter
Attack
Evidence from
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 12,529 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/spinner/jquery.ui.spinner.js?v=20220209161352
Method GET
Parameter
Attack
Evidence TODO
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 12,529 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/spinner/jquery.ui.spinner.js?v=20220209161352
Method GET
Parameter
Attack
Evidence user
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 12,529 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/spinner/jquery.ui.spinner.js?v=20220209161352
Method GET
Parameter
Attack
Evidence where
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 12,529 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/splitter/js/jquery.splitter-0.14.0.js?v=20220209161352
Method GET
Parameter
Attack
Evidence later
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 11,897 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence admin
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence from
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence select
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence DB
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence from
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence select
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 30
Solution
Remove all comments that return information that may help an attacker and fix any underlying problems they refer to.
Reference
Tags OWASP_2021_A01
OWASP_2017_A03
CWE Id 200
WASC Id 13
Plugin Id 10027
Informational
Information Exposure Through HTML Comments (script)
Description
While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/pis.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 457 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,760 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 4
Solution
Remove comments which have sensitive information about the design/implementation of the application. Some of the comments may be exposed to the user and affect the security posture of the application.
Reference
Tags
CWE Id 615
WASC Id 13
Plugin Id 50001
Informational
Non-Storable Content
Description
The response contents are not storable by caching components such as proxy servers. If the response does not contain sensitive, personal or user-specific information, it may benefit from being stored and cached, to improve performance.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/login_applist.php
Method GET
Parameter
Attack
Evidence no-store
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 19,058 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/print_git_version_pdf.php
Method GET
Parameter
Attack
Evidence private
Request Header - size: 450 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,285 bytes.
Response Body - size: 7,040 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/view_payrollgroup.php
Method GET
Parameter
Attack
Evidence no-store
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 61,300 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/main.php
Method POST
Parameter
Attack
Evidence no-store
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,165 bytes.
Response Body - size: 46,741 bytes.
Instances 4
Solution
The content may be marked as storable by ensuring that the following conditions are satisfied:

The request method must be understood by the cache and defined as being cacheable ("GET", "HEAD", and "POST" are currently defined as cacheable)

The response status code must be understood by the cache (one of the 1XX, 2XX, 3XX, 4XX, or 5XX response classes are generally understood)

The "no-store" cache directive must not appear in the request or response header fields

For caching by "shared" caches such as "proxy" caches, the "private" response directive must not appear in the response

For caching by "shared" caches such as "proxy" caches, the "Authorization" header field must not appear in the request, unless the response explicitly allows it (using one of the "must-revalidate", "public", or "s-maxage" Cache-Control response directives)

In addition to the conditions above, at least one of the following conditions must also be satisfied by the response:

It must contain an "Expires" header field

It must contain a "max-age" response directive

For "shared" caches such as "proxy" caches, it must contain a "s-maxage" response directive

It must contain a "Cache Control Extension" that allows it to be cached

It must have a status code that is defined as cacheable by default (200, 203, 204, 206, 300, 301, 404, 405, 410, 414, 501).
Reference https://tools.ietf.org/html/rfc7234
https://tools.ietf.org/html/rfc7231
http://www.w3.org/Protocols/rfc2616/rfc2616-sec13.html (obsoleted by rfc7234)
Tags WSTG-v42-ATHN-06
CWE Id 524
WASC Id 13
Plugin Id 10049
Informational
Storable and Cacheable Content
Description
The response contents are storable by caching components such as proxy servers, and may be retrieved directly from the cache, rather than from the origin server by the caching servers, in response to similar requests from other users. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where "shared" caching servers such as "proxy" caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/img/lst.png
Method GET
Parameter
Attack
Evidence
Request Header - size: 432 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,108 bytes.
Response Body - size: 31,568 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/greaterdate_function.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 472 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 2,104 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/jquery.blockUI.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 20,322 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/lst_freeze_table/lst_freeze_table.css?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 486 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 3,066 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/lst_freeze_table/lst_freeze_table.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 485 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 9,219 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/sha1.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 456 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 3,459 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/javascript/shadedborder.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 464 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 9,626 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/alertify.min.js?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 33,298 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/css/alertify.min.css?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 471 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 19,192 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/alertify/css/themes/bootstrap.min.css?v=20220209161346
Method GET
Parameter
Attack
Evidence
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,243 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/css/blue_style/jquery-ui-1.10.4.custom.css?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 498 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,130 bytes.
Response Body - size: 32,089 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-1.10.2.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 479 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 273,199 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/1.10.4/js/jquery-ui-1.10.4.custom.min.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,145 bytes.
Response Body - size: 228,560 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/jquery.cookie.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 465 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,143 bytes.
Response Body - size: 1,940 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.css?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 481 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,789 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/jquery/timepicker/jquery.timepicker.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 34,511 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/spinner/jquery.ui.spinner.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 480 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 12,529 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/splitter/css/jquery.splitter.css?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 484 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,393 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/lib/spinsplit/splitter/js/jquery.splitter-0.14.0.js?v=20220209161352
Method GET
Parameter
Attack
Evidence
Request Header - size: 489 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,144 bytes.
Response Body - size: 11,897 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/images/logout.gif
Method GET
Parameter
Attack
Evidence
Request Header - size: 442 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,106 bytes.
Response Body - size: 979 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/images/userlog1.gif
Method GET
Parameter
Attack
Evidence
Request Header - size: 444 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,107 bytes.
Response Body - size: 1,065 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/greenpastures.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 467 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,128 bytes.
Response Body - size: 797 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/main.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 458 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 5,269 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/main_loader.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 465 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,131 bytes.
Response Body - size: 101,812 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/pis.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 457 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,760 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/splitter.css
Method GET
Parameter
Attack
Evidence
Request Header - size: 445 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,128 bytes.
Response Body - size: 638 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/style.fluid.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 465 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,128 bytes.
Response Body - size: 467 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/styleSheet1.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 465 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,355 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/table_design.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 466 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,129 bytes.
Response Body - size: 1,407 bytes.
URL http://192.168.2.47/online_test/web_standard_onedb/webapp/tkm/tkm_css/toolbar.css?v=20220209161358
Method GET
Parameter
Attack
Evidence
Request Header - size: 461 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,128 bytes.
Response Body - size: 409 bytes.
URL http://192.168.2.47/robots.txt
Method GET
Parameter
Attack
Evidence
Request Header - size: 299 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/sitemap.xml
Method GET
Parameter
Attack
Evidence
Request Header - size: 300 bytes.
Request Body - size: 0 bytes.
Response Header - size: 906 bytes.
Response Body - size: 196 bytes.
URL http://192.168.2.47/webprog_generic_login/onedb/webapp/login.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 222 bytes.
Request Body - size: 0 bytes.
Response Header - size: 1,055 bytes.
Response Body - size: 34,194 bytes.
Instances 33
Solution
Validate that the response does not contain sensitive, personal or user-specific information. If it does, consider the use of the following HTTP response headers, to limit, or prevent the content being stored and retrieved from the cache by another user:

Cache-Control: no-cache, no-store, must-revalidate, private

Pragma: no-cache

Expires: 0

This configuration directs both HTTP 1.0 and HTTP 1.1 compliant caching servers to not store the response, and to not retrieve the response (without validation) from the cache, in response to a similar request.
Reference https://tools.ietf.org/html/rfc7234
https://tools.ietf.org/html/rfc7231
http://www.w3.org/Protocols/rfc2616/rfc2616-sec13.html (obsoleted by rfc7234)
Tags WSTG-v42-ATHN-06
CWE Id 524
WASC Id 13
Plugin Id 10049