官术网_书友最值得收藏!

Nonqualifying vulnerabilities

This section lists all of the vulnerabilities that are explicitly out of scope. It lists the vulnerabilities that have been reported before or are not considered as critical enough to be reported. This is usually a long list of vulnerabilities that include commonly reported issues, such as:

  • Bugs in content/services that are not owned/operated by the program
  • Vulnerabilities affecting users of unsupported browsers
  • Subdomain takeovers for out-of-scope domains
  • Self-XSS or XSS bugs requiring an unlikely amount of user interaction
  • CSRF on forms that are available to anonymous users
  • Clickjacking that is, user interface hijacking on static pages
  • Error messages
  • HTTP 404 codes/pages or other HTTP non-200 code/pages
  • Fingerprinting banner disclosure-public information disclosure
  • Disclosure of known public files or directories+
  • Scripting or other automation and brute forcing of intended functionalities
  • Presence of application or web browser "autocomplete" or "save password" functionality
  • Lack of secure and HttpOnly cookie flags
  • HTTPS mixed content
  • Missing HTTP security headers, specifically-Strict-Transport-Security, X-Frame-Options, X-XSS-Protection, X-Content-Type-Options, and Content-Security-Policy
主站蜘蛛池模板: 巢湖市| 晋宁县| 五河县| 黔东| 肥城市| 霍城县| 梧州市| 清河县| 郴州市| 天峻县| 深泽县| 绍兴市| 博爱县| 慈利县| 蓝山县| 若尔盖县| 龙岩市| 东安县| 乳山市| 宝丰县| 青神县| 澄江县| 大邑县| 澄江县| 丹巴县| 十堰市| 百色市| 新建县| 曲阳县| 西畴县| 龙山县| 乌苏市| 定安县| 金坛市| 平乡县| 定日县| 华容县| 平山县| 黄冈市| 特克斯县| 清镇市|