Generated on Mon, 12 Dec 2022 23:07:17

Summary of Alerts

Risk Level Number of Alerts
High
4
Medium
6
Low
3
Informational
5

Passing Rules

Name Rule Type Threshold Strength
Directory Browsing Active MEDIUM MEDIUM
CRLF Injection Active MEDIUM MEDIUM
Path Traversal Active MEDIUM MEDIUM
Remote File Inclusion Active MEDIUM MEDIUM
Parameter Tampering Active MEDIUM MEDIUM
Server Side Include Active MEDIUM MEDIUM
GET for POST Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) Active MEDIUM MEDIUM
Script Active Scan Rules Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) - Prime Active MEDIUM MEDIUM
Cross Site Scripting (Persistent) - Spider Active MEDIUM MEDIUM
SQL Injection - Hypersonic SQL Active MEDIUM MEDIUM
SQL Injection - Oracle Active MEDIUM MEDIUM
SQL Injection - PostgreSQL Active MEDIUM MEDIUM
SQL Injection - SQLite Active MEDIUM MEDIUM
SQL Injection - MsSQL Active MEDIUM MEDIUM
ELMAH Information Leak Active MEDIUM MEDIUM
Trace.axd Information Leak Active MEDIUM MEDIUM
.env Information Leak Active MEDIUM MEDIUM
Server Side Code Injection Active MEDIUM MEDIUM
Hidden File Finder Active MEDIUM MEDIUM
Remote OS Command Injection Active MEDIUM MEDIUM
XML External Entity Attack Active MEDIUM MEDIUM
Generic Padding Oracle Active MEDIUM MEDIUM
SOAP Action Spoofing Active MEDIUM MEDIUM
SOAP XML Injection Active MEDIUM MEDIUM
Heartbleed OpenSSL Vulnerability Active MEDIUM MEDIUM
Buffer Overflow Active MEDIUM MEDIUM
Source Code Disclosure - CVE-2012-1823 Active MEDIUM MEDIUM
Format String Error Active MEDIUM MEDIUM
Remote Code Execution - CVE-2012-1823 Active MEDIUM MEDIUM
Cloud Metadata Potentially Exposed Active MEDIUM MEDIUM
External Redirect Active MEDIUM MEDIUM
Source Code Disclosure - /WEB-INF folder Active MEDIUM MEDIUM
Private IP Disclosure Passive MEDIUM -
Session ID in URL Rewrite Passive MEDIUM -
Insecure JSF ViewState Passive MEDIUM -
Vulnerable JS Library (Powered by Retire.js) Passive MEDIUM -
Cookie No HttpOnly Flag Passive MEDIUM -
Cookie Without Secure Flag Passive MEDIUM -
Re-examine Cache-control Directives Passive MEDIUM -
Cross-Domain JavaScript Source File Inclusion Passive MEDIUM -
Content-Type Header Missing Passive MEDIUM -
Application Error Disclosure Passive MEDIUM -
Information Disclosure - Debug Error Messages Passive MEDIUM -
Information Disclosure - Sensitive Information in URL Passive MEDIUM -
Information Disclosure - Sensitive Information in HTTP Referrer Header Passive MEDIUM -
Open Redirect Passive MEDIUM -
Cookie Poisoning Passive MEDIUM -
User Controllable Charset Passive MEDIUM -
WSDL File Detection Passive MEDIUM -
Loosely Scoped Cookie Passive MEDIUM -
Viewstate Passive MEDIUM -
Heartbleed OpenSSL Vulnerability (Indicative) Passive MEDIUM -
Strict-Transport-Security Header Passive MEDIUM -
X-Backend-Server Header Information Leak Passive MEDIUM -
Secure Pages Include Mixed Content Passive MEDIUM -
HTTP to HTTPS Insecure Transition in Form Post Passive MEDIUM -
HTTPS to HTTP Insecure Transition in Form Post Passive MEDIUM -
User Controllable JavaScript Event (XSS) Passive MEDIUM -
Big Redirect Detected (Potential Sensitive Information Leak) Passive MEDIUM -
Retrieved from Cache Passive MEDIUM -
X-ChromeLogger-Data (XCOLD) Header Information Leak Passive MEDIUM -
Cookie without SameSite Attribute Passive MEDIUM -
CSP Passive MEDIUM -
X-Debug-Token Information Leak Passive MEDIUM -
Username Hash Found Passive MEDIUM -
X-AspNet-Version Response Header Passive MEDIUM -
PII Disclosure Passive MEDIUM -
Script Passive Scan Rules Passive MEDIUM -
Stats Passive Scan Rule Passive MEDIUM -
Timestamp Disclosure Passive MEDIUM -
Hash Disclosure Passive MEDIUM -
Cross-Domain Misconfiguration Passive MEDIUM -
Weak Authentication Method Passive MEDIUM -
Reverse Tabnabbing Passive MEDIUM -

Sites

http://testphp.vulnweb.com

HTTP Response Code Number of Responses
403 Forbidden
2
404 Not Found
660
405 Method Not Allowed
20
200 OK
6627
301 Moved Permanently
238
302 Found
235

No Authentication Statistics Found

Parameter Name Type Flags Times Used # Values

Alert Detail

High
Cross Site Scripting (DOM Based)
Description
Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user's browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.

When an attacker gets a user's browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.

There are three types of Cross-site Scripting attacks: non-persistent, persistent and DOM-based.

Non-persistent attacks and DOM-based attacks require a user to either visit a specially crafted link laced with malicious code, or visit a malicious web page containing a web form, which when posted to the vulnerable site, will mount the attack. Using a malicious form will oftentimes take place when the vulnerable resource only accepts HTTP POST requests. In such a case, the form can be submitted automatically, without the victim's knowledge (e.g. by using JavaScript). Upon clicking on the malicious link or submitting the malicious form, the XSS payload will get echoed back and will get interpreted by the user's browser and execute. Another technique to send almost arbitrary requests (GET and POST) is by using an embedded client, such as Adobe Flash.

Persistent attacks occur when the malicious code is submitted to a web site where it's stored for a period of time. Examples of an attacker's favorite targets often include message board posts, web mail messages, and web chat software. The unsuspecting user is not required to interact with any additional site/link (e.g. an attacker site or a malicious link sent via email), just simply view the web page containing the code.
URL http://testphp.vulnweb.com#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 347 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/artists.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 396 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3?name=abc#<img src="random.gif" onerror=alert(5397)>
Method GET
Parameter
Attack ?name=abc#<img src="random.gif" onerror=alert(5397)>
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/cart.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 393 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/categories.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 399 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/disclaimer.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 399 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/guestbook.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 398 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/index.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 394 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6?name=abc#<img src="random.gif" onerror=alert(5397)>
Method GET
Parameter
Attack ?name=abc#<img src="random.gif" onerror=alert(5397)>
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/signup.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method GET
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 404 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/userinfo.php?name=abc#<img src="random.gif" onerror=alert(5397)>
Method GET
Parameter
Attack ?name=abc#<img src="random.gif" onerror=alert(5397)>
Evidence
Request Header - size: 263 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/cart.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method POST
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 347 bytes.
Request Body - size: 21 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/guestbook.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method POST
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 517 bytes.
Request Body - size: 52 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/search.php?test=query#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method POST
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/userinfo.php#jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Method POST
Parameter
Attack #jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e
Evidence
Request Header - size: 343 bytes.
Request Body - size: 18 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
Instances 18
Solution
Phase: Architecture and Design

Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and Apache Wicket.

Phases: Implementation; Architecture and Design

Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messages. Study all expected communication protocols and data representations to determine the required encoding strategies.

For any data that will be output to another web page, especially any data that was received from external inputs, use the appropriate encoding on all non-alphanumeric characters.

Consult the XSS Prevention Cheat Sheet for more details on the types of encoding and escaping that are needed.

Phase: Architecture and Design

For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.

If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated.

Phase: Implementation

For every web page that is generated, use and specify a character encoding such as ISO-8859-1 or UTF-8. When an encoding is not specified, the web browser may choose a different encoding by guessing which encoding is actually being used by the web page. This can cause the web browser to treat certain sequences as special, opening up the client to subtle XSS attacks. See CWE-116 for more mitigations related to encoding/escaping.

To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to malicious client-side scripts that use document.cookie. This is not a complete solution, since HttpOnly is not supported by all browsers. More importantly, XMLHTTPRequest and other powerful browser technologies provide read access to HTTP headers, including the Set-Cookie header in which the HttpOnly flag is set.

Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use an allow list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. Do not rely exclusively on looking for malicious or malformed inputs (i.e., do not rely on a deny list). However, deny lists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.

When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if you are expecting colors such as "red" or "blue."

Ensure that you perform input validation at well-defined interfaces within the application. This will help protect the application even if a component is reused or moved elsewhere.
Reference http://projects.webappsec.org/Cross-Site-Scripting
http://cwe.mitre.org/data/definitions/79.html
Tags WSTG-v42-CLNT-01
OWASP_2021_A03
OWASP_2017_A07
CWE Id 79
WASC Id 8
Plugin Id 40026
High
Cross Site Scripting (Reflected)
Description
Cross-site Scripting (XSS) is an attack technique that involves echoing attacker-supplied code into a user's browser instance. A browser instance can be a standard web browser client, or a browser object embedded in a software product such as the browser within WinAmp, an RSS reader, or an email client. The code itself is usually written in HTML/JavaScript, but may also extend to VBScript, ActiveX, Java, Flash, or any other browser-supported technology.

When an attacker gets a user's browser to execute his/her code, the code will run within the security context (or zone) of the hosting web site. With this level of privilege, the code has the ability to read, modify and transmit any sensitive data accessible by the browser. A Cross-site Scripted user could have his/her account hijacked (cookie theft), their browser redirected to another location, or possibly shown fraudulent content delivered by the web site they are visiting. Cross-site Scripting attacks essentially compromise the trust relationship between a user and the web site. Applications utilizing browser object instances which load content from the file system may execute code under the local machine zone allowing for system compromise.

There are three types of Cross-site Scripting attacks: non-persistent, persistent and DOM-based.

Non-persistent attacks and DOM-based attacks require a user to either visit a specially crafted link laced with malicious code, or visit a malicious web page containing a web form, which when posted to the vulnerable site, will mount the attack. Using a malicious form will oftentimes take place when the vulnerable resource only accepts HTTP POST requests. In such a case, the form can be submitted automatically, without the victim's knowledge (e.g. by using JavaScript). Upon clicking on the malicious link or submitting the malicious form, the XSS payload will get echoed back and will get interpreted by the user's browser and execute. Another technique to send almost arbitrary requests (GET and POST) is by using an embedded client, such as Adobe Flash.

Persistent attacks occur when the malicious code is submitted to a web site where it's stored for a period of time. Examples of an attacker's favorite targets often include message board posts, web mail messages, and web chat software. The unsuspecting user is not required to interact with any additional site/link (e.g. an attacker site or a malicious link sent via email), just simply view the web page containing the code.
URL http://testphp.vulnweb.com/hpp/?pp=javascript%3Aalert%281%29%3B
Method GET
Parameter pp
Attack javascript:alert(1);
Evidence javascript:alert(1);
Request Header - size: 292 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 445 bytes.
URL http://testphp.vulnweb.com/hpp/params.php?p=%3CscrIpt%3Ealert%281%29%3B%3C%2FscRipt%3E&pp=12
Method GET
Parameter p
Attack <scrIpt>alert(1);</scRipt>
Evidence <scrIpt>alert(1);</scRipt>
Request Header - size: 327 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 28 bytes.
URL http://testphp.vulnweb.com/hpp/params.php?p=valid&pp=%3CscrIpt%3Ealert%281%29%3B%3C%2FscRipt%3E
Method GET
Parameter pp
Attack <scrIpt>alert(1);</scRipt>
Evidence <scrIpt>alert(1);</scRipt>
Request Header - size: 330 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 31 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=%3Cimg+src%3Dx+onerror%3Dprompt%28%29%3E
Method GET
Parameter artist
Attack <img src=x onerror=prompt()>
Evidence <img src=x onerror=prompt()>
Request Header - size: 336 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,004 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=%3Cimg+src%3Dx+onerror%3Dprompt%28%29%3E
Method GET
Parameter cat
Attack <img src=x onerror=prompt()>
Evidence <img src=x onerror=prompt()>
Request Header - size: 327 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,004 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter name
Attack </strong><scrIpt>alert(1);</scRipt><strong>
Evidence </strong><scrIpt>alert(1);</scRipt><strong>
Request Header - size: 518 bytes.
Request Body - size: 107 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,441 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter text
Attack </td><scrIpt>alert(1);</scRipt><td>
Evidence </td><scrIpt>alert(1);</scRipt><td>
Request Header - size: 518 bytes.
Request Body - size: 105 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,439 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter searchFor
Attack </h2><scrIpt>alert(1);</scRipt><h2>
Evidence </h2><scrIpt>alert(1);</scRipt><h2>
Request Header - size: 342 bytes.
Request Body - size: 83 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,804 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter uaddress
Attack </li><scrIpt>alert(1);</scRipt><li>
Evidence </li><scrIpt>alert(1);</scRipt><li>
Request Header - size: 521 bytes.
Request Body - size: 176 bytes.
Response Header - size: 221 bytes.
Response Body - size: 790 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter ucc
Attack </li><scrIpt>alert(1);</scRipt><li>
Evidence </li><scrIpt>alert(1);</scRipt><li>
Request Header - size: 521 bytes.
Request Body - size: 176 bytes.
Response Header - size: 221 bytes.
Response Body - size: 790 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter uemail
Attack </li><scrIpt>alert(1);</scRipt><li>
Evidence </li><scrIpt>alert(1);</scRipt><li>
Request Header - size: 521 bytes.
Request Body - size: 176 bytes.
Response Header - size: 221 bytes.
Response Body - size: 790 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter uphone
Attack </li><scrIpt>alert(1);</scRipt><li>
Evidence </li><scrIpt>alert(1);</scRipt><li>
Request Header - size: 521 bytes.
Request Body - size: 176 bytes.
Response Header - size: 221 bytes.
Response Body - size: 790 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter urname
Attack </li><scrIpt>alert(1);</scRipt><li>
Evidence </li><scrIpt>alert(1);</scRipt><li>
Request Header - size: 521 bytes.
Request Body - size: 176 bytes.
Response Header - size: 221 bytes.
Response Body - size: 790 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter uuname
Attack </li><scrIpt>alert(1);</scRipt><li>
Evidence </li><scrIpt>alert(1);</scRipt><li>
Request Header - size: 521 bytes.
Request Body - size: 176 bytes.
Response Header - size: 221 bytes.
Response Body - size: 790 bytes.
Instances 14
Solution
Phase: Architecture and Design

Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and Apache Wicket.

Phases: Implementation; Architecture and Design

Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messages. Study all expected communication protocols and data representations to determine the required encoding strategies.

For any data that will be output to another web page, especially any data that was received from external inputs, use the appropriate encoding on all non-alphanumeric characters.

Consult the XSS Prevention Cheat Sheet for more details on the types of encoding and escaping that are needed.

Phase: Architecture and Design

For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.

If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated.

Phase: Implementation

For every web page that is generated, use and specify a character encoding such as ISO-8859-1 or UTF-8. When an encoding is not specified, the web browser may choose a different encoding by guessing which encoding is actually being used by the web page. This can cause the web browser to treat certain sequences as special, opening up the client to subtle XSS attacks. See CWE-116 for more mitigations related to encoding/escaping.

To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to malicious client-side scripts that use document.cookie. This is not a complete solution, since HttpOnly is not supported by all browsers. More importantly, XMLHTTPRequest and other powerful browser technologies provide read access to HTTP headers, including the Set-Cookie header in which the HttpOnly flag is set.

Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use an allow list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. Do not rely exclusively on looking for malicious or malformed inputs (i.e., do not rely on a deny list). However, deny lists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.

When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if you are expecting colors such as "red" or "blue."

Ensure that you perform input validation at well-defined interfaces within the application. This will help protect the application even if a component is reused or moved elsewhere.
Reference http://projects.webappsec.org/Cross-Site-Scripting
http://cwe.mitre.org/data/definitions/79.html
Tags OWASP_2021_A03
WSTG-v42-INPV-01
OWASP_2017_A07
CWE Id 79
WASC Id 8
Plugin Id 40012
High
SQL Injection
Description
SQL injection may be possible
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=5-2
Method GET
Parameter id
Attack 5-2
Evidence
Request Header - size: 313 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,285 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=6-2
Method GET
Parameter id
Attack 6-2
Evidence
Request Header - size: 312 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 324 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=5-2
Method GET
Parameter artist
Attack 5-2
Evidence
Request Header - size: 285 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3+AND+1%3D1+--+
Method GET
Parameter artist
Attack 3 OR 1=1 --
Evidence
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4+AND+1%3D1+--+
Method GET
Parameter cat
Attack 4 OR 1=1 --
Evidence
Request Header - size: 302 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/product.php?pic=8-2
Method GET
Parameter pic
Attack 8-2
Evidence
Request Header - size: 293 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter uuname
Attack akpnUdBu' OR '1'='1' --
Evidence
Request Header - size: 521 bytes.
Request Body - size: 152 bytes.
Response Header - size: 221 bytes.
Response Body - size: 780 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter pass
Attack ZAP' OR '1'='1' --
Evidence
Request Header - size: 343 bytes.
Request Body - size: 47 bytes.
Response Header - size: 244 bytes.
Response Body - size: 14 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter uname
Attack ZAP' OR '1'='1' --
Evidence
Request Header - size: 343 bytes.
Request Body - size: 47 bytes.
Response Header - size: 244 bytes.
Response Body - size: 14 bytes.
Instances 9
Solution
Do not trust client side input, even if there is client side validation in place.

In general, type check all data on the server side.

If the application uses JDBC, use PreparedStatement or CallableStatement, with parameters passed by '?'

If the application uses ASP, use ADO Command Objects with strong type checking and parameterized queries.

If database Stored Procedures can be used, use them.

Do *not* concatenate strings into queries in the stored procedure, or use 'exec', 'exec immediate', or equivalent functionality!

Do not create dynamic SQL queries using simple string concatenation.

Escape all data received from the client.

Apply an 'allow list' of allowed characters, or a 'deny list' of disallowed characters in user input.

Apply the privilege of least privilege by using the least privileged database user possible.

In particular, avoid using the 'sa' or 'db-owner' database users. This does not eliminate SQL injection, but minimizes its impact.

Grant the minimum database access that is necessary for the application.
Reference https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
Tags OWASP_2021_A03
WSTG-v42-INPV-05
OWASP_2017_A01
CWE Id 89
WASC Id 19
Plugin Id 40018
High
SQL Injection - MySQL
Description
SQL injection may be possible
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=3
Method GET
Parameter id
Attack 3 / sleep(15)
Evidence
Request Header - size: 330 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=4
Method GET
Parameter id
Attack 4 / sleep(15)
Evidence
Request Header - size: 329 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter artist
Attack 3 / sleep(15)
Evidence
Request Header - size: 302 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,942 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter pic
Attack 6 / sleep(15)
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 14 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter uname
Attack ZAP' / sleep(15) / '
Evidence
Request Header - size: 343 bytes.
Request Body - size: 47 bytes.
Response Header - size: 244 bytes.
Response Body - size: 14 bytes.
Instances 5
Solution
Do not trust client side input, even if there is client side validation in place.

In general, type check all data on the server side.

If the application uses JDBC, use PreparedStatement or CallableStatement, with parameters passed by '?'

If the application uses ASP, use ADO Command Objects with strong type checking and parameterized queries.

If database Stored Procedures can be used, use them.

Do *not* concatenate strings into queries in the stored procedure, or use 'exec', 'exec immediate', or equivalent functionality!

Do not create dynamic SQL queries using simple string concatenation.

Escape all data received from the client.

Apply an 'allow list' of allowed characters, or a 'deny list' of disallowed characters in user input.

Apply the privilege of least privilege by using the least privileged database user possible.

In particular, avoid using the 'sa' or 'db-owner' database users. This does not eliminate SQL injection, but minimizes its impact.

Grant the minimum database access that is necessary for the application.
Reference https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
Tags OWASP_2021_A03
WSTG-v42-INPV-05
OWASP_2017_A01
CWE Id 89
WASC Id 19
Plugin Id 40019
Medium
.htaccess Information Leak
Description
htaccess files can be used to alter the configuration of the Apache Web Server software to enable/disable additional functionality and features that the Apache Web Server software has to offer.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/.htaccess
Method GET
Parameter
Attack
Evidence HTTP/1.1 200 OK
Request Header - size: 277 bytes.
Request Body - size: 0 bytes.
Response Header - size: 252 bytes.
Response Body - size: 176 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/.htaccess
Method GET
Parameter
Attack
Evidence HTTP/1.1 200 OK
Request Header - size: 319 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/.htaccess
Method GET
Parameter
Attack
Evidence HTTP/1.1 200 OK
Request Header - size: 336 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/.htaccess
Method GET
Parameter
Attack
Evidence HTTP/1.1 200 OK
Request Header - size: 323 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
Instances 4
Solution
Ensure the .htaccess file is not accessible.
Reference http://www.htaccess-guide.com/
Tags OWASP_2021_A05
WSTG-v42-CONF-05
OWASP_2017_A06
CWE Id 94
WASC Id 14
Plugin Id 40032
Medium
Absence of Anti-CSRF Tokens
Description
No Anti-CSRF tokens were found in a HTML submission form.

A cross-site request forgery is an attack that involves forcing a victim to send an HTTP request to a target destination without their knowledge or intent in order to perform an action as the victim. The underlying cause is application functionality using predictable URL/form actions in a repeatable way. The nature of the attack is that CSRF exploits the trust that a web site has for a user. By contrast, cross-site scripting (XSS) exploits the trust that a user has for a web site. Like XSS, CSRF attacks are not necessarily cross-site, but they can be. Cross-site request forgery is also known as CSRF, XSRF, one-click attack, session riding, confused deputy, and sea surf.

CSRF attacks are effective in a number of situations, including:

* The victim has an active session on the target site.

* The victim is authenticated via HTTP auth on the target site.

* The victim is on the same local network as the target site.

CSRF has primarily been used to perform an action against a target site using the victim's privileges, but recent techniques have been discovered to disclose information by gaining access to the response. The risk of information disclosure is dramatically increased when the target site is vulnerable to XSS, because XSS can be used as a platform for CSRF, allowing the attack to operate within the bounds of the same-origin policy.
URL http://testphp.vulnweb.com
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 447 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/cart.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/categories.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,115 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=1
Method GET
Parameter
Attack
Evidence <form action="comment.php" method="post" enctype="application/x-www-form-urlencoded" name="fComment" id="fComment">
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=2
Method GET
Parameter
Attack
Evidence <form action="comment.php" method="post" enctype="application/x-www-form-urlencoded" name="fComment" id="fComment">
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3
Method GET
Parameter
Attack
Evidence <form action="comment.php" method="post" enctype="application/x-www-form-urlencoded" name="fComment" id="fComment">
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/disclaimer.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,524 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter
Attack
Evidence <form action="" method="post" name="faddentry">
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/index.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=3
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter
Attack
Evidence <form name="loginform" method="post" action="userinfo.php">
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter
Attack
Evidence <form name='f_addcart' method='POST' action='cart.php'>
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter
Attack
Evidence <form name='f_addcart' method='POST' action='cart.php'>
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter
Attack
Evidence <form name='f_addcart' method='POST' action='cart.php'>
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter
Attack
Evidence <form name='f_addcart' method='POST' action='cart.php'>
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter
Attack
Evidence <form name='f_addcart' method='POST' action='cart.php'>
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter
Attack
Evidence <form name='f_addcart' method='POST' action='cart.php'>
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter
Attack
Evidence <form name='f_addcart' method='POST' action='cart.php'>
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter
Attack
Evidence <form name="form1" method="post" action="/secured/newuser.php">
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/cart.php
Method POST
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 347 bytes.
Request Body - size: 19 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter
Attack
Evidence <form action="" method="post" name="faddentry">
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter
Attack
Evidence <form action="search.php?test=query" method="post">
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
Instances 44
Solution
Phase: Architecture and Design

Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.

For example, use anti-CSRF packages such as the OWASP CSRFGuard.

Phase: Implementation

Ensure that your application is free of cross-site scripting issues, because most CSRF defenses can be bypassed using attacker-controlled script.

Phase: Architecture and Design

Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330).

Note that this can be bypassed using XSS.

Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.

Note that this can be bypassed using XSS.

Use the ESAPI Session Management control.

This control includes a component for CSRF.

Do not use the GET method for any request that triggers a state change.

Phase: Implementation

Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.
Reference http://projects.webappsec.org/Cross-Site-Request-Forgery
http://cwe.mitre.org/data/definitions/352.html
Tags OWASP_2021_A01
WSTG-v42-SESS-05
OWASP_2017_A05
CWE Id 352
WASC Id 9
Plugin Id 10202
Medium
Content Security Policy (CSP) Header Not Set
Description
Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.
URL http://testphp.vulnweb.com
Method GET
Parameter
Attack
Evidence
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter
Attack
Evidence
Request Header - size: 447 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/cart.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/categories.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,115 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/disclaimer.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,524 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/high
Method GET
Parameter
Attack
Evidence
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 153 bytes.
URL http://testphp.vulnweb.com/hpp/
Method GET
Parameter
Attack
Evidence
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp/?pp=12
Method GET
Parameter
Attack
Evidence
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 383 bytes.
URL http://testphp.vulnweb.com/hpp/params.php?p=valid&pp=12
Method GET
Parameter
Attack
Evidence
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 7 bytes.
URL http://testphp.vulnweb.com/images/
Method GET
Parameter
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/index.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/
Method GET
Parameter
Attack
Evidence
Request Header - size: 268 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter
Attack
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter
Attack
Evidence
Request Header - size: 327 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter
Attack
Evidence
Request Header - size: 314 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/privacy.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 227 bytes.
Response Body - size: 16 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/robots.txt
Method GET
Parameter
Attack
Evidence
Request Header - size: 224 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 153 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/sitemap.xml
Method GET
Parameter
Attack
Evidence
Request Header - size: 225 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 153 bytes.
URL http://testphp.vulnweb.com/cart.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 347 bytes.
Request Body - size: 19 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter
Attack
Evidence
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 351 bytes.
Request Body - size: 96 bytes.
Response Header - size: 221 bytes.
Response Body - size: 733 bytes.
Instances 47
Solution
Ensure that your web server, application server, load balancer, etc. is configured to set the Content-Security-Policy header, to achieve optimal browser support: "Content-Security-Policy" for Chrome 25+, Firefox 23+ and Safari 7+, "X-Content-Security-Policy" for Firefox 4.0+ and Internet Explorer 10+, and "X-WebKit-CSP" for Chrome 14+ and Safari 6+.
Reference https://developer.mozilla.org/en-US/docs/Web/Security/CSP/Introducing_Content_Security_Policy
https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html
http://www.w3.org/TR/CSP/
http://w3c.github.io/webappsec/specs/content-security-policy/csp-specification.dev.html
http://www.html5rocks.com/en/tutorials/security/content-security-policy/
http://caniuse.com/#feat=contentsecuritypolicy
http://content-security-policy.com/
Tags OWASP_2021_A05
OWASP_2017_A06
CWE Id 693
WASC Id 15
Plugin Id 10038
Medium
Directory Browsing - Apache 2
Description
It is possible to view a listing of the directory contents. Directory listings may reveal hidden scripts, include files , backup source files, etc., which be accessed to reveal sensitive information. - Apache 2
URL http://testphp.vulnweb.com/images/
Method GET
Parameter
Attack
Evidence <title>Index of /images/</title>
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
Instances 1
Solution
Configure the web server to disable directory browsing.
Reference https://cwe.mitre.org/data/definitions/548.html
Tags OWASP_2021_A05
OWASP_2017_A06
CWE Id 548
WASC Id 16
Plugin Id 10033
Medium
Missing Anti-clickjacking Header
Description
The response does not include either Content-Security-Policy with 'frame-ancestors' directive or X-Frame-Options to protect against 'ClickJacking' attacks.
URL http://testphp.vulnweb.com
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 447 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/cart.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/categories.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,115 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=1
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=2
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/disclaimer.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,524 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/hpp/
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp/?pp=12
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 383 bytes.
URL http://testphp.vulnweb.com/hpp/params.php?p=valid&pp=12
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 7 bytes.
URL http://testphp.vulnweb.com/images/
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/index.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=3
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 268 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 327 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 314 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/cart.php
Method POST
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 347 bytes.
Request Body - size: 19 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter X-Frame-Options
Attack
Evidence
Request Header - size: 351 bytes.
Request Body - size: 96 bytes.
Response Header - size: 221 bytes.
Response Body - size: 733 bytes.
Instances 43
Solution
Modern Web browsers support the Content-Security-Policy and X-Frame-Options HTTP headers. Ensure one of them is set on all web pages returned by your site/app.

If you expect the page to be framed only by pages on your server (e.g. it's part of a FRAMESET) then you'll want to use SAMEORIGIN, otherwise if you never expect the page to be framed, you should use DENY. Alternatively consider implementing Content Security Policy's "frame-ancestors" directive.
Reference https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options
Tags OWASP_2021_A05
WSTG-v42-CLNT-09
OWASP_2017_A06
CWE Id 1021
WASC Id 15
Plugin Id 10020
Medium
XSLT Injection
Description
Injection using XSL transformations may be possible, and may allow an attacker to read system information, read and write files, or execute arbitrary code.
URL http://testphp.vulnweb.com/showimage.php?file=%3Cxsl%3Avalue-of+select%3D%22document%28%27http%3A%2F%2Ftestphp.vulnweb.com%3A22%27%29%22%2F%3E
Method GET
Parameter file
Attack <xsl:value-of select="document('http://testphp.vulnweb.com:22')"/>
Evidence failed to open stream
Request Header - size: 389 bytes.
Request Body - size: 0 bytes.
Response Header - size: 207 bytes.
Response Body - size: 286 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=%3Cxsl%3Avalue-of+select%3D%22document%28%27http%3A%2F%2Ftestphp.vulnweb.com%3A22%27%29%22%2F%3E&size=160
Method GET
Parameter file
Attack <xsl:value-of select="document('http://testphp.vulnweb.com:22')"/>
Evidence failed to open stream
Request Header - size: 398 bytes.
Request Body - size: 0 bytes.
Response Header - size: 207 bytes.
Response Body - size: 286 bytes.
Instances 2
Solution
Sanitize and analyze every user input coming from any client-side.
Reference https://www.contextis.com/blog/xslt-server-side-injection-attacks
Tags OWASP_2021_A03
OWASP_2017_A01
CWE Id 91
WASC Id 23
Plugin Id 90017
Low
Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)
Description
The web/application server is leaking information via one or more "X-Powered-By" HTTP response headers. Access to such information may facilitate attackers identifying other frameworks/components your web application is reliant upon and the vulnerabilities such components may be subject to.
URL http://testphp.vulnweb.com
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 447 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/AJAX/artists.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 303 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 146 bytes.
URL http://testphp.vulnweb.com/AJAX/categories.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 306 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 195 bytes.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=1
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,343 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=2
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,285 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=3
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,285 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=1
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 323 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=2
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 325 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=3
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 324 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=4
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 324 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/cart.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/categories.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,115 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=1
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=2
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/disclaimer.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,524 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/hpp/
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp/?pp=12
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 383 bytes.
URL http://testphp.vulnweb.com/hpp/params.php?p=valid&pp=12
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 7 bytes.
URL http://testphp.vulnweb.com/index.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=3
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 268 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 327 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 314 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/privacy.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 227 bytes.
Response Body - size: 16 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/showimage.php?file='%20+%20pict.item(0).firstChild.nodeValue%20+%20'
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 334 bytes.
Request Body - size: 0 bytes.
Response Header - size: 207 bytes.
Response Body - size: 261 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/1.jpg
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 12,426 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/1.jpg&size=160
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 12,426 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/2.jpg
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 3,324 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/2.jpg&size=160
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 3,324 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/3.jpg
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 9,692 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/3.jpg&size=160
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 9,692 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/4.jpg
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 13,969 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/4.jpg&size=160
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 13,969 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/5.jpg
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 14,228 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/5.jpg&size=160
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 14,228 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/6.jpg
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 11,465 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/6.jpg&size=160
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 11,465 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/7.jpg
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 19,219 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/7.jpg&size=160
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 19,219 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 263 bytes.
Request Body - size: 0 bytes.
Response Header - size: 244 bytes.
Response Body - size: 14 bytes.
URL http://testphp.vulnweb.com/cart.php
Method POST
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 347 bytes.
Request Body - size: 19 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 351 bytes.
Request Body - size: 96 bytes.
Response Header - size: 221 bytes.
Response Body - size: 733 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter
Attack
Evidence X-Powered-By: PHP/5.6.40-38+ubuntu20.04.1+deb.sury.org+1
Request Header - size: 343 bytes.
Request Body - size: 18 bytes.
Response Header - size: 244 bytes.
Response Body - size: 14 bytes.
Instances 69
Solution
Ensure that your web server, application server, load balancer, etc. is configured to suppress "X-Powered-By" headers.
Reference http://blogs.msdn.com/b/varunm/archive/2013/04/23/remove-unwanted-http-response-headers.aspx
http://www.troyhunt.com/2012/02/shhh-dont-let-your-response-headers.html
Tags OWASP_2021_A01
WSTG-v42-INFO-08
OWASP_2017_A03
CWE Id 200
WASC Id 13
Plugin Id 10037
Low
Server Leaks Version Information via "Server" HTTP Response Header Field
Description
The web/application server is leaking version information via the "Server" HTTP response header. Access to such information may facilitate attackers identifying other vulnerabilities your web/application server is subject to.
URL http://testphp.vulnweb.com
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 447 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/AJAX/artists.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 303 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 146 bytes.
URL http://testphp.vulnweb.com/AJAX/categories.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 306 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 195 bytes.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=1
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,343 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=2
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,285 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=3
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,285 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=1
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 323 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=2
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 325 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=3
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 324 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=4
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 324 bytes.
URL http://testphp.vulnweb.com/AJAX/styles.css
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 281 bytes.
Request Body - size: 0 bytes.
Response Header - size: 237 bytes.
Response Body - size: 562 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/cart.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/categories.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,115 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=1
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=2
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/disclaimer.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,524 bytes.
URL http://testphp.vulnweb.com/favicon.ico
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 306 bytes.
Request Body - size: 0 bytes.
Response Header - size: 241 bytes.
Response Body - size: 894 bytes.
URL http://testphp.vulnweb.com/Flash/add.swf
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 261 bytes.
Response Body - size: 17,418 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/high
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 153 bytes.
URL http://testphp.vulnweb.com/hpp/
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp/?pp=12
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 383 bytes.
URL http://testphp.vulnweb.com/hpp/params.php?p=valid&pp=12
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 7 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 220 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 169 bytes.
URL http://testphp.vulnweb.com/images/
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images/logo.gif
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 6,660 bytes.
URL http://testphp.vulnweb.com/images/remark.gif
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 282 bytes.
Request Body - size: 0 bytes.
Response Header - size: 236 bytes.
Response Body - size: 79 bytes.
URL http://testphp.vulnweb.com/index.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=3
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 268 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 327 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 314 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images/1.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 3,551 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images/2.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 2,739 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images/3.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 3,560 bytes.
URL http://testphp.vulnweb.com/privacy.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 227 bytes.
Response Body - size: 16 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/robots.txt
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 224 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 153 bytes.
URL http://testphp.vulnweb.com/secured/style.css
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 239 bytes.
Response Body - size: 5,482 bytes.
URL http://testphp.vulnweb.com/showimage.php?file='%20+%20pict.item(0).firstChild.nodeValue%20+%20'
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 334 bytes.
Request Body - size: 0 bytes.
Response Header - size: 207 bytes.
Response Body - size: 261 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/1.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 12,426 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/1.jpg&size=160
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 12,426 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/2.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 3,324 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/2.jpg&size=160
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 3,324 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/3.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 9,692 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/3.jpg&size=160
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 9,692 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/4.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 13,969 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/4.jpg&size=160
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 13,969 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/5.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 14,228 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/5.jpg&size=160
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 14,228 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/6.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 11,465 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/6.jpg&size=160
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 11,465 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/7.jpg
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 19,219 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/7.jpg&size=160
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 19,219 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/sitemap.xml
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 225 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 153 bytes.
URL http://testphp.vulnweb.com/style.css
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 375 bytes.
Request Body - size: 0 bytes.
Response Header - size: 239 bytes.
Response Body - size: 5,482 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 263 bytes.
Request Body - size: 0 bytes.
Response Header - size: 244 bytes.
Response Body - size: 14 bytes.
URL http://testphp.vulnweb.com/cart.php
Method POST
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 347 bytes.
Request Body - size: 19 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 351 bytes.
Request Body - size: 96 bytes.
Response Header - size: 221 bytes.
Response Body - size: 733 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter
Attack
Evidence nginx/1.19.0
Request Header - size: 343 bytes.
Request Body - size: 18 bytes.
Response Header - size: 244 bytes.
Response Body - size: 14 bytes.
Instances 84
Solution
Ensure that your web server, application server, load balancer, etc. is configured to suppress the "Server" header or provide generic details.
Reference http://httpd.apache.org/docs/current/mod/core.html#servertokens
http://msdn.microsoft.com/en-us/library/ff648552.aspx#ht_urlscan_007
http://blogs.msdn.com/b/varunm/archive/2013/04/23/remove-unwanted-http-response-headers.aspx
http://www.troyhunt.com/2012/02/shhh-dont-let-your-response-headers.html
Tags OWASP_2021_A05
OWASP_2017_A06
WSTG-v42-INFO-02
CWE Id 200
WASC Id 13
Plugin Id 10036
Low
X-Content-Type-Options Header Missing
Description
The Anti-MIME-Sniffing header X-Content-Type-Options was not set to 'nosniff'. This allows older versions of Internet Explorer and Chrome to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the declared content type. Current (early 2014) and legacy versions of Firefox will use the declared content type (if one is set), rather than performing MIME-sniffing.
URL http://testphp.vulnweb.com
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 447 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/AJAX/artists.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 303 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 146 bytes.
URL http://testphp.vulnweb.com/AJAX/categories.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 306 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 195 bytes.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=1
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,343 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=2
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,285 bytes.
URL http://testphp.vulnweb.com/AJAX/infoartist.php?id=3
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 220 bytes.
Response Body - size: 1,285 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=1
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 323 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=2
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 325 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=3
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 324 bytes.
URL http://testphp.vulnweb.com/AJAX/infocateg.php?id=4
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 324 bytes.
URL http://testphp.vulnweb.com/AJAX/styles.css
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 281 bytes.
Request Body - size: 0 bytes.
Response Header - size: 237 bytes.
Response Body - size: 562 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/cart.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/categories.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,115 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=1
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=2
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/disclaimer.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,524 bytes.
URL http://testphp.vulnweb.com/favicon.ico
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 306 bytes.
Request Body - size: 0 bytes.
Response Header - size: 241 bytes.
Response Body - size: 894 bytes.
URL http://testphp.vulnweb.com/Flash/add.swf
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 261 bytes.
Response Body - size: 17,418 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/hpp/
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp/?pp=12
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 383 bytes.
URL http://testphp.vulnweb.com/hpp/params.php?p=valid&pp=12
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 7 bytes.
URL http://testphp.vulnweb.com/images/
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images/logo.gif
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 6,660 bytes.
URL http://testphp.vulnweb.com/images/remark.gif
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 282 bytes.
Request Body - size: 0 bytes.
Response Header - size: 236 bytes.
Response Body - size: 79 bytes.
URL http://testphp.vulnweb.com/index.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=3
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 268 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 327 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 314 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images/1.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 3,551 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images/2.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 2,739 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images/3.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 240 bytes.
Response Body - size: 3,560 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/secured/style.css
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 239 bytes.
Response Body - size: 5,482 bytes.
URL http://testphp.vulnweb.com/showimage.php?file='%20+%20pict.item(0).firstChild.nodeValue%20+%20'
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 334 bytes.
Request Body - size: 0 bytes.
Response Header - size: 207 bytes.
Response Body - size: 261 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/1.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 12,426 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/1.jpg&size=160
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 12,426 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/2.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 3,324 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/2.jpg&size=160
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 3,324 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/3.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 9,692 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/3.jpg&size=160
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 208 bytes.
Response Body - size: 9,692 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/4.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 13,969 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/4.jpg&size=160
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 13,969 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/5.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 14,228 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/5.jpg&size=160
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 14,228 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/6.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 11,465 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/6.jpg&size=160
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 11,465 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/7.jpg
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 19,219 bytes.
URL http://testphp.vulnweb.com/showimage.php?file=./pictures/7.jpg&size=160
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 209 bytes.
Response Body - size: 19,219 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/style.css
Method GET
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 375 bytes.
Request Body - size: 0 bytes.
Response Header - size: 239 bytes.
Response Body - size: 5,482 bytes.
URL http://testphp.vulnweb.com/cart.php
Method POST
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 347 bytes.
Request Body - size: 19 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter X-Content-Type-Options
Attack
Evidence
Request Header - size: 351 bytes.
Request Body - size: 96 bytes.
Response Header - size: 221 bytes.
Response Body - size: 733 bytes.
Instances 77
Solution
Ensure that the application/web server sets the Content-Type header appropriately, and that it sets the X-Content-Type-Options header to 'nosniff' for all web pages.

If possible, ensure that the end user uses a standards-compliant and modern web browser that does not perform MIME-sniffing at all, or that can be directed by the web application/web server to not perform MIME-sniffing.
Reference http://msdn.microsoft.com/en-us/library/ie/gg622941%28v=vs.85%29.aspx
https://owasp.org/www-community/Security_Headers
Tags OWASP_2021_A05
OWASP_2017_A06
CWE Id 693
WASC Id 15
Plugin Id 10021
Informational
Charset Mismatch (Header Versus Meta Content-Type Charset)
Description
This check identifies responses where the HTTP Content-Type header declares a charset different from the charset defined by the body of the HTML or XML. When there's a charset mismatch between the HTTP header and content body Web browsers can be forced into an undesirable content-sniffing mode to determine the content's correct character set.

An attacker could manipulate content on the page to be interpreted in an encoding of their choice. For example, if an attacker can control content at the beginning of the page, they could inject script using UTF-7 encoded text and manipulate some browsers into interpreting that text.
URL http://testphp.vulnweb.com
Method GET
Parameter
Attack
Evidence
Request Header - size: 213 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter
Attack
Evidence
Request Header - size: 447 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/cart.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/categories.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,115 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/comment.php?aid=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 413 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 1,252 bytes.
URL http://testphp.vulnweb.com/disclaimer.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,524 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/index.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=4
Method GET
Parameter
Attack
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,699 bytes.
URL http://testphp.vulnweb.com/login.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/product.php?pic=1
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,428 bytes.
URL http://testphp.vulnweb.com/product.php?pic=2
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,368 bytes.
URL http://testphp.vulnweb.com/product.php?pic=3
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,401 bytes.
URL http://testphp.vulnweb.com/product.php?pic=4
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,453 bytes.
URL http://testphp.vulnweb.com/product.php?pic=5
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,382 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,454 bytes.
URL http://testphp.vulnweb.com/product.php?pic=7
Method GET
Parameter
Attack
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,734 bytes.
URL http://testphp.vulnweb.com/signup.php
Method GET
Parameter
Attack
Evidence
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,033 bytes.
URL http://testphp.vulnweb.com/cart.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 347 bytes.
Request Body - size: 19 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,903 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter
Attack
Evidence
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
URL http://testphp.vulnweb.com/secured/newuser.php
Method POST
Parameter
Attack
Evidence
Request Header - size: 351 bytes.
Request Body - size: 96 bytes.
Response Header - size: 221 bytes.
Response Body - size: 733 bytes.
Instances 35
Solution
Force UTF-8 for all text content in both the HTTP header and meta tags in HTML or encoding declarations in XML.
Reference http://code.google.com/p/browsersec/wiki/Part2#Character_set_handling_and_detection
Tags
CWE Id 436
WASC Id 15
Plugin Id 90011
Informational
Information Disclosure - Suspicious Comments
Description
The response appears to contain suspicious comments which may help an attacker. Note: Matches made within script blocks or files are against the entire content not only comments.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter
Attack
Evidence where
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
Instances 1
Solution
Remove all comments that return information that may help an attacker and fix any underlying problems they refer to.
Reference
Tags OWASP_2021_A01
OWASP_2017_A03
CWE Id 200
WASC Id 13
Plugin Id 10027
Informational
Modern Web Application
Description
The application appears to be a modern web application. If you need to explore it automatically then the Ajax Spider may well be more effective than the standard one.
URL http://testphp.vulnweb.com/AJAX/index.php
Method GET
Parameter
Attack
Evidence <a href="#" onclick="loadSomething('titles.php')">titles</a>
Request Header - size: 265 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?aid=1','comment','width=500,height=400')">comment on this artist</a>
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=1
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?aid=1','comment','width=500,height=400')">comment on this artist</a>
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,251 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=2
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?aid=2','comment','width=500,height=400')">comment on this artist</a>
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/artists.php?artist=3
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?aid=3','comment','width=500,height=400')">comment on this artist</a>
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 6,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=1
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?pid=1','comment','width=500,height=400')">comment on this picture</a>
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,994 bytes.
URL http://testphp.vulnweb.com/listproducts.php?artist=2
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?pid=7','comment','width=500,height=400')">comment on this picture</a>
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,193 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=1
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?pid=1','comment','width=500,height=400')">comment on this picture</a>
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 7,880 bytes.
URL http://testphp.vulnweb.com/listproducts.php?cat=2
Method GET
Parameter
Attack
Evidence <a href='#' onClick="window.open('./comment.php?pid=6','comment','width=500,height=400')">comment on this picture</a>
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,311 bytes.
Instances 9
Solution
This is an informational alert and so no changes are required.
Reference
Tags
CWE Id
WASC Id
Plugin Id 10109
Informational
User Agent Fuzzer
Description
Check for differences in response based on fuzzed User Agent (eg. mobile sites, access as a Search Engine Crawler). Compares the response statuscode and the hashcode of the response body with the original response.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 317 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 317 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 317 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 329 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 395 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 382 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 345 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 339 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 350 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 403 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 408 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 313 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,958 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 219 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 219 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 219 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 231 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 284 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 247 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 241 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 252 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 305 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 310 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/AJAX
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 215 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,236 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 366 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 366 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 366 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 378 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 444 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 431 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 394 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 388 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 399 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 452 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 457 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/artists.php
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 362 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,328 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 220 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 220 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 220 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 232 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 285 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 248 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 242 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 253 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 306 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/Flash
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 216 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 371 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 368 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 368 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 368 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 380 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 446 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 433 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 396 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 390 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 401 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 454 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 459 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 364 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,390 bytes.
URL http://testphp.vulnweb.com/high
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 219 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/high
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 219 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/high
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 219 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/high
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 297 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/high
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 284 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 218 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 218 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 218 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 230 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 296 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 246 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 240 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 251 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 304 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/hpp
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 214 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 203 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 184 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 184 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 184 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 196 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 262 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 249 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 212 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 206 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 217 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 270 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 275 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/images
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 180 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 377 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 231 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 231 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 231 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 243 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 309 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 296 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 259 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 253 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 264 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 317 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 322 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 227 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 975 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 257 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 257 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 257 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 335 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 322 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 271 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 349 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 336 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 273 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 273 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 273 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 351 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 338 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 274 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 274 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 274 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 286 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 352 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 339 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 302 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 296 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 307 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 360 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 365 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/color-printer/3/
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 270 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 313 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 366 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 353 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 368 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 355 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 291 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 303 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 369 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 356 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 319 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 313 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 324 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 377 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 382 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/network-attached-storage-dlink/1/
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 287 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 319 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 275 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 275 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 275 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 353 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 340 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 277 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 277 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 277 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 355 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 342 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 290 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 356 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 343 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 306 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 300 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 364 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 369 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/Details/web-camera-a4tech/2/
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 274 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 279 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 256 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 256 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 256 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 268 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 334 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 321 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 284 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 278 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 289 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 342 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 347 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/Mod_Rewrite_Shop/images
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 252 bytes.
Request Body - size: 0 bytes.
Response Header - size: 148 bytes.
Response Body - size: 513 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 333 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 320 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 283 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 277 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 288 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 341 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 346 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/product.php?pic=6
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 251 bytes.
Request Body - size: 0 bytes.
Response Header - size: 221 bytes.
Response Body - size: 170 bytes.
URL http://testphp.vulnweb.com/robots.txt
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 188 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/robots.txt
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 188 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/robots.txt
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 188 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/robots.txt
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/robots.txt
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 253 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 233 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 245 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 311 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 298 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 261 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 266 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 319 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 324 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/secured
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 229 bytes.
Request Body - size: 0 bytes.
Response Header - size: 219 bytes.
Response Body - size: 0 bytes.
URL http://testphp.vulnweb.com/sitemap.xml
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 189 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/sitemap.xml
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 189 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/sitemap.xml
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 189 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/sitemap.xml
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 267 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/sitemap.xml
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 254 bytes.
Request Body - size: 0 bytes.
Response Header - size: 155 bytes.
Response Body - size: 555 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 227 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 227 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 227 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 239 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 305 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 292 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 255 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 249 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 260 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 313 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 318 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method GET
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 223 bytes.
Request Body - size: 0 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 487 bytes.
Request Body - size: 52 bytes.
Response Header - size: 217 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 487 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 487 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 499 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 565 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 552 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 515 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 509 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 520 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 573 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 578 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 483 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Request Header - size: 307 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Request Header - size: 307 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Request Header - size: 307 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko
Evidence
Request Header - size: 319 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3739.0 Safari/537.36 Edg/75.0.109.0
Evidence
Request Header - size: 385 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Evidence
Request Header - size: 372 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/91.0
Evidence
Request Header - size: 335 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Evidence
Request Header - size: 329 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Evidence
Request Header - size: 340 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; CPU iPhone OS 8_0_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12A366 Safari/600.1.4
Evidence
Request Header - size: 393 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac OS X; en-us) AppleWebKit/528.18 (KHTML, like Gecko) Version/4.0 Mobile/7A341 Safari/528.16
Evidence
Request Header - size: 398 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
URL http://testphp.vulnweb.com/userinfo.php
Method POST
Parameter Header User-Agent
Attack msnbot/1.1 (+http://search.msn.com/msnbot.htm)
Evidence
Request Header - size: 303 bytes.
Request Body - size: 18 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,523 bytes.
Instances 250
Solution
Reference https://owasp.org/wstg
Tags
CWE Id
WASC Id
Plugin Id 10104
Informational
User Controllable HTML Element Attribute (Potential XSS)
Description
This check looks at user-supplied input in query string parameters and POST data to identify where certain HTML attribute values might be controlled. This provides hot-spot detection for XSS (cross-site scripting) that will require further review by a security analyst to determine exploitability.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter name
Attack
Evidence
Request Header - size: 517 bytes.
Request Body - size: 52 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,412 bytes.
URL http://testphp.vulnweb.com/guestbook.php
Method POST
Parameter submit
Attack
Evidence
Request Header - size: 348 bytes.
Request Body - size: 33 bytes.
Response Header - size: 222 bytes.
Response Body - size: 5,393 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter goButton
Attack
Evidence
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
URL http://testphp.vulnweb.com/search.php?test=query
Method POST
Parameter goButton
Attack
Evidence
Request Header - size: 342 bytes.
Request Body - size: 25 bytes.
Response Header - size: 222 bytes.
Response Body - size: 4,772 bytes.
Instances 4
Solution
Validate all input and sanitize output it before writing to any HTML attributes.
Reference http://websecuritytool.codeplex.com/wikipage?title=Checks#user-controlled-html-attribute
Tags OWASP_2021_A03
OWASP_2017_A01
CWE Id 20
WASC Id 20
Plugin Id 10031