Back to Zaproxy

OWASP ZAP watcher results

python/scripts/watcher/report-v1.4.0.1.html

2015-06-254.5 KB
Original Source

OWASP ZAP watcher results

Generated: 2012-07-13 18:27

Total Score

26%
Pass: 11
Fail: 31
Total: 42

Detailed Results

PageResultPassFailOther
Check.Pasv.Asp.Net.ViewState.Mac.phpFAIL&nbspXFrame XContent
Check.Pasv.Charset.Mismatch.phpFAIL&nbspXFrame XContent
Check.Pasv.Charset.Utf8.phpFAIL&nbspXFrame XContent
Check.Pasv.Cookie.HttpOnly.phpPASS&nbspHttpOnlyXFrame XContent
Check.Pasv.Cookie.LooselyScoped.phpFAIL&nbspXFrame XContent
Check.Pasv.Cookie.Secure.phpPASS&nbspInsecureCookieXFrame CacheControl XContent
Check.Pasv.CrossDomain.FormSubmit.phpFAIL&nbspXFrame CSRF XContent
Check.Pasv.CrossDomain.JavascriptReference.phpFAIL&nbspXFrame XContent
Check.Pasv.CrossDomain.ScriptReference.phpPASS&nbspCrossJSXFrame XContent
Check.Pasv.CrossDomain.StyleSheetInclusion.phpFAIL&nbspXFrame XContent
Check.Pasv.Flash.AllowScriptAccess.phpFAIL&nbspXFrame XContent
Check.Pasv.Flash.CrossDomain.phpFAIL&nbspXFrame XContent
Check.Pasv.Header.CacheControl.phpPASS&nbspCacheControlXFrame XContent
Check.Pasv.Header.ContentTypeMissing.phpPASS&nbspXContentNoContentHeader
Check.Pasv.Header.FrameOptions.phpPASS&nbspXFrameXContent
Check.Pasv.Header.IeXssProtection.phpFAIL&nbspXFrame IE8XSSfilter XContent
Check.Pasv.Header.InternalIp.phpFAIL&nbspXFrame XContent
Check.Pasv.Header.MimeSniff.phpPASS&nbspNoContentHeaderXContent
Check.Pasv.Header.WeakAuth.phpPASS&nbspWeakAuthXFrame XContent
Check.Pasv.InformationDisclosure.Comments.phpFAIL&nbspXFrame XContent
Check.Pasv.InformationDisclosure.DatabaseErrors.phpPASS&nbspInfoDbXFrame XContent
Check.Pasv.InformationDisclosure.DebugErrors.phpPASS&nbspInfoDebugXFrame XContent
Check.Pasv.InformationDisclosure.InUrl.phpPASS&nbspInfoUrlXFrame XContent
Check.Pasv.InformationDisclosure.ReferrerLeak.phpFAIL&nbspInfoUrl XFrame XContent
Check.Pasv.Java.ViewState.Uncompressed.phpFAIL&nbspXFrame XContent
Check.Pasv.Java.ViewState.phpFAIL&nbspXFrame XContent
Check.Pasv.Javascript.DomainLowering.phpFAIL&nbspXFrame XContent
Check.Pasv.Javascript.Eval.phpFAIL&nbspXFrame XContent
Check.Pasv.SSL.CertValidation.phpFAIL&nbspXFrame CacheControl XContent
Check.Pasv.SSL.InsecureFormLoad.phpFAIL&nbspXFrame CSRF XContent
Check.Pasv.SSL.InsecureFormPost.phpFAIL&nbspXFrame CacheControl CSRF XContent
Check.Pasv.SSL.StrictTransportSecurity.phpFAIL&nbspXFrame CacheControl XContent
Check.Pasv.SSL.Version.phpFAIL&nbspXFrame CacheControl XContent
Check.Pasv.SharePoint.DocLib.phpFAIL&nbspXFrame XContent
Check.Pasv.Silverlight.ClientAccessPolicy.phpFAIL&nbspXFrame XContent
Check.Pasv.Silverlight.EnableHtmlAccess.phpFAIL&nbspXFrame XContent
Check.Pasv.Unicode.InvalidUTF8.phpFAIL&nbspXFrame XContent
Check.Pasv.UserControlled.Charset.phpFAIL&nbspXFrame XContent
Check.Pasv.UserControlled.Cookie.phpFAIL&nbspXFrame XContent
Check.Pasv.UserControlled.HtmlAttributes.phpFAIL&nbspXFrame CSRF XContent
Check.Pasv.UserControlled.JavascriptEvent.phpFAIL&nbspXFrame CSRF XContent
Check.Pasv.UserControlled.JavascriptProperty.phpFAIL&nbspXFrame XContent

Alerts Key

AlertDescription
AutoPassword Autocomplete in browser
CSRFCross Site Request Forgery
CacheControlIncomplete or no cache-control and pragma HTTPHeader set
CrossJSCross-domain JavaScript source file inclusion
HttpOnlyCookie set without HttpOnly flag
IE8XSSfilterIE8's XSS protection filter not disabled
InfoDbInformation disclosure - database error messages
InfoDebugInformation disclosure - debug error messages
InfoUrlInformation disclosure - sensitive informations in URL
InsecureCookieCookie set without secure flag
NoContentHeaderContent-Type header missing
SQLfpSQL Injection Fingerprinting
SQLiSQL Injection
WeakAuthWeak HTTP authentication over an unsecured connection
XContentX-Content-Type-Options header missing
XFrameX-Frame-Options header not set
XSSCross Site Scripting