How to remediate – IBM WebSphere Portal Unspecified JSP XSS (PI16040) 1. Introduction The IBM WebSphere Portal Unspecified JSP XSS (PI16040) vulnerability allows an attacker to execute code in a user’s...
How to remediate – Insecure Client-Access Policy 1. Introduction The “Insecure Client-Access Policy” vulnerability occurs when a Silverlight application’s `ClientAccessPolicy.xml` file is configured too permissively, allowing cross-domain...
How to remediate – ImpressPages Detection 1. Introduction ImpressPages Detection identifies instances of the ImpressPages content management system running on a web server. This is an...
How to remediate – Inductive Automation Ignition Detection 1. Introduction Inductive Automation Ignition Detection indicates that a web-based SCADA HMI solution is running on the remote host. This...
How to remediate – iniNet SpiderControl SCADA Web Server Detection 1. Introduction The iniNet SpiderControl SCADA Web Server Detection indicates a web server used for managing and monitoring Programmable Logic...
How to remediate – InMail/InShop inmail.pl / inshop.pl XSS 1. Introduction The InMail/InShop application is vulnerable to a cross-site scripting (XSS) attack in the ‘inmail.pl’ and ‘inshop.pl’ scripts. This...
How to remediate – Input Reflected 1. Introduction Input Reflected is a vulnerability where user-supplied data is immediately returned in the response without proper sanitisation. This...
How to remediate – Insecure ‘Access-Control-Allow-Origin’ Header 1. Introduction The ‘Access-Control-Allow-Origin’ vulnerability occurs when a web application incorrectly configures Cross-Origin Resource Sharing (CORS) headers, specifically by setting...
How to remediate – Insecure Cross-Domain Policy (allow-access-from) 1. Introduction Insecure Cross-Domain Policy (allow-access-from) occurs when a website’s `crossdomain.xml` file is configured too permissively, allowing any domain to...
How to remediate – Insecure Cross-Domain Policy (allow-http-request-headers-from) 1. Introduction Insecure Cross-Domain Policy (allow-http-request-headers-from) occurs when a website’s `crossdomain.xml` file is configured too permissively, allowing any domain to...