官术网_书友最值得收藏!

Nonqualifying vulnerabilities

This section lists all of the vulnerabilities that are explicitly out of scope. It lists the vulnerabilities that have been reported before or are not considered as critical enough to be reported. This is usually a long list of vulnerabilities that include commonly reported issues, such as:

  • Bugs in content/services that are not owned/operated by the program
  • Vulnerabilities affecting users of unsupported browsers
  • Subdomain takeovers for out-of-scope domains
  • Self-XSS or XSS bugs requiring an unlikely amount of user interaction
  • CSRF on forms that are available to anonymous users
  • Clickjacking that is, user interface hijacking on static pages
  • Error messages
  • HTTP 404 codes/pages or other HTTP non-200 code/pages
  • Fingerprinting banner disclosure-public information disclosure
  • Disclosure of known public files or directories+
  • Scripting or other automation and brute forcing of intended functionalities
  • Presence of application or web browser "autocomplete" or "save password" functionality
  • Lack of secure and HttpOnly cookie flags
  • HTTPS mixed content
  • Missing HTTP security headers, specifically-Strict-Transport-Security, X-Frame-Options, X-XSS-Protection, X-Content-Type-Options, and Content-Security-Policy
主站蜘蛛池模板: 武宁县| 海原县| 桑植县| 乌恰县| 景泰县| 萍乡市| 定州市| 宜州市| 广宁县| 金阳县| 介休市| 抚顺县| 平顶山市| 洛扎县| 凤翔县| 西安市| 巴林左旗| 新和县| 辉县市| 小金县| 丰城市| 吐鲁番市| 高安市| 慈利县| 柏乡县| 区。| 江津市| 拉萨市| 阆中市| 屏东市| 改则县| 宜君县| 聂荣县| 沅江市| 广饶县| 磐石市| 新绛县| 武功县| 辰溪县| 略阳县| 唐河县|