Vulnerability Name
Classifications
Severity
Database Connection String Detected
CWE-16, HIPAA-164.306(a), ISO27001-A.18.1.3, WASC-15, OWASP 2013-A5, OWASP 2017-A3, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Information
Deprecated Header Instruction Used to Implement Content Security Policy (CSP)
CWE-16, ISO27001-A.14.2.5, WASC-15
Information
HTTP Strict Transport Security (HSTS) Max-Age Value Too Low
CWE-16, ISO27001-A.14.1.2, WASC-15
Information
HTTP Strict Transport Security (HSTS) via HTTP
CWE-16, ISO27001-A.14.1.2, WASC-15, OWASP 2017-A6
Information
Incorrect Content Security Policy (CSP) Implementation
CWE-16, ISO27001-A.14.2.5, WASC-15, OWASP 2013-A5, OWASP 2017-A6
Information
Invalid Content Security Policy (CSP) Directive Identified in meta Elements
CWE-16, ISO27001-A.14.2.5, WASC-15, OWASP 2013-A5, OWASP 2017-A6
Information
Missing frame-ancestors in CSP Declaration
CWE-16, ISO27001-A.14.2.5, WASC-15
Information
Missing object-src in CSP Declaration
CWE-16, ISO27001-A.14.2.5, WASC-15
Information
Multiple Content Security Policy (CSP) Implementation Detected
CWE-16, ISO27001-A.14.2.5, WASC-15
Information
OPTIONS Method Enabled
CAPEC-107, CWE-16, ISO27001-A.14.1.2, WASC-14, OWASP 2013-A5, OWASP 2017-A6
Information
Retired Hash Function in SAML Response
CWE-16
Information
Static Nonce Identified in Content Security Policy (CSP)
CWE-16, ISO27001-A.14.2.5, WASC-15, OWASP 2013-A5, OWASP 2017-A6
Information