Vulnerability Name
Classifications
Severity
Sensitive Data Exposure – Twilio API Key
PCI v3.2-6.5.6, CAPEC-37, CWE-200, ISO27001-A.8.2.1, WASC-WASC-13, OWASP 2013-A6, OWASP 2017-A3, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Medium
Sensitive Data Exposure – Twitter API Secret Key
PCI v3.2-6.5.6, CAPEC-37, CWE-200, ISO27001-A.8.2.1, WASC-WASC-13, OWASP 2013-A6, OWASP 2017-A3, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Medium
Sensitive Data Exposure – Twitter Access Token Secret
PCI v3.2-6.5.6, CAPEC-37, CWE-200, ISO27001-A.8.2.1, WASC-WASC-13, OWASP 2013-A6, OWASP 2017-A3, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Medium
Sensitive Data Exposure – WordPress Authentication Key/Salt
PCI v3.2-6.5.6, CAPEC-37, CWE-200, ISO27001-A.8.2.1, WASC-WASC-13, OWASP 2013-A6, OWASP 2017-A3, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Medium
Information Disclosure (Microsoft Office)
PCI v3.2-6.5.5, CAPEC-118, CWE-200, ISO27001-A.18.1.3, WASC-13
Low
Internal IP Address Disclosure
CWE-200, ISO27001-A.18.1.4, OWASP 2013-A6, OWASP 2017-A3
Low
Version Disclosure (Varnish)
CAPEC-224, CWE-200, ISO27001-A.18.1.3, WASC-45
Low
Windows Username Disclosure
PCI v3.2-6.5.5, CAPEC-118, CWE-200, ISO27001-A.18.1.3, WASC-13, OWASP 2013-A6, OWASP 2017-A3
Low
Referrer-Policy Not Implemented
CWE-200, ISO27001-A.14.2.5, OWASP 2013-A6, OWASP 2017-A3
Best Practice
CDN Detected (Airee)
CAPEC-224, CWE-200, ISO27001-A.18.1.3, WASC-45
Information
CDN Detected (Akamai)
CAPEC-224, CWE-200, ISO27001-A.18.1.3, WASC-45
Information
CDN Detected (Arvan Cloud)
CAPEC-224, CWE-200, ISO27001-A.18.1.3, WASC-45
Information