Vulnerability Name
Classifications
Severity
Misconfigured Frame
CWE-16, ISO27001-A.14.1.2, WASC-15, OWASP 2017-A6
Low
Missing Content-Type Header
PCI v3.2-6.5.7, CWE-16, ISO27001-A.14.1.2, WASC-15, OWASP 2013-A5, OWASP 2017-A6
Low
Missing X-Content-Type-Options Header
CWE-16, ISO27001-A.14.1.2, WASC-15, OWASP 2013-A5, OWASP 2017-A6
Low
PHP allow_url_fopen Is Enabled
CWE-16, OWASP 2013-A5, OWASP 2017-A6
Low
PHP allow_url_include Is Enabled
CWE-16, OWASP 2013-A5, OWASP 2017-A6
Low
PHP open_basedir Is Not Configured
CWE-16, OWASP 2013-A5, OWASP 2017-A6
Low
Phishing by Navigating Browser Tabs
CWE-16, ISO27001-A.14.1.2, WASC-15, OWASP 2013-A5, OWASP 2017-A6
Low
RoR Development Mode Enabled
PCI v3.2-6.5.5, CAPEC-214, CWE-16, ISO27001-A.14.1.1, WASC-14, OWASP 2013-A5, OWASP 2017-A6
Low
Struts2 Development Mode Enabled
PCI v3.2-6.5.5, CAPEC-214, CWE-16, ISO27001-A.18.1.3, WASC-14, OWASP 2013-A5, OWASP 2017-A6
Low
Subresource Integrity (SRI) Hash Invalid
CWE-16, ISO27001-A.14.2.5, WASC-15
Low
TRACE/TRACK Method Detected
CAPEC-107, CWE-16, ISO27001-A.14.1.2, WASC-14, OWASP 2013-A5, OWASP 2017-A6
Low
ViewState is not Encrypted
CWE-16, HIPAA-164.306(a), 164.308(a), ISO27001-A.14.2.5, WASC-15, OWASP 2017-A6
Low