🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
vulnerabilities categorized as
Low
severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Apache Multiple Choices Enabled
Apache Multiple Choices Enabled
CWE-16
,Â
ISO27001-A.9.4.1
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-14
,Â
Low
Apache MultiViews Enabled
Apache MultiViews Enabled
CWE-16
,Â
ISO27001-A.9.4.1
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-14
,Â
Low
ASP.NET ViewStateUserKey Is Not Set
ASP.NET ViewStateUserKey Is Not Set
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Autocomplete is Enabled
Autocomplete is Enabled
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
AWS Dockerrun Configuration File Detected
AWS Dockerrun Configuration File Detected
CAPEC-118
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
,Â
CWE-527
,Â
ISO27001-A9.4.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
Backup File Disclosure
Backup File Disclosure
CAPEC-87
,Â
CWE-530
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
PCI v3.2-6.5.8
,Â
WASC-34
,Â
Low
Cookie Not Marked as HttpOnly
Cookie Not Marked as HttpOnly
CAPEC-107
,Â
CWE-16
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
Cookie Not Marked as Secure
Cookie Not Marked as Secure
CAPEC-102
,Â
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
,Â
CWE-614
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.10
,Â
WASC-15
,Â
Low
Cookie Values Used in Anti-CSRF Token
Cookie Values Used in Anti-CSRF Token
CWE-352
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Cross-site Request Forgery
Cross-site Request Forgery
CAPEC-62
,Â
CWE-352
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A8
,Â
OWASP 2017-A5
,Â
PCI v3.2-6.5.9
,Â
WASC-9
,Â
Low
Cross-site Request Forgery in Login Form
Cross-site Request Forgery in Login Form
CAPEC-62
,Â
CWE-352
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A8
,Â
OWASP 2017-A5
,Â
PCI v3.2-6.5.9
,Â
WASC-9
,Â
Low
Database Error Message Disclosure
Database Error Message Disclosure
CAPEC-118
,Â
CWE-210
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Database Name Disclosure (Microsoft SQL Server)
Database Name Disclosure (Microsoft SQL Server)
CAPEC-118
,Â
CWE-201
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Database Name Disclosure (MySQL)
Database Name Disclosure (MySQL)
CAPEC-118
,Â
CWE-201
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Django Debug Mode Enabled
Django Debug Mode Enabled
CAPEC-214
,Â
CWE-16
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Docker Cloud Stack File Detected
Docker Cloud Stack File Detected
CAPEC-118
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
,Â
CWE-527
,Â
ISO27001-A9.4.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
Docker Compose File Detected
Docker Compose File Detected
CAPEC-118
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
,Â
CWE-527
,Â
ISO27001-A9.4.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
Dockerfile Detected
Dockerfile Detected
CAPEC-118
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
,Â
CWE-527
,Â
ISO27001-A9.4.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
.dockerignore File Detected
.dockerignore File Detected
CAPEC-118
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
,Â
CWE-527
,Â
ISO27001-A9.4.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
.DS_Store File Found
.DS_Store File Found
CWE-284
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
PCI v3.2-6.5.8
,Â
WASC-2
,Â
Low
Exception Report Disclosure (Tomcat)
Exception Report Disclosure (Tomcat)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Form Hijacking
Form Hijacking
CWE-20
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
WASC-20
,Â
Low
Information Disclosure (Microsoft Office)
Information Disclosure (Microsoft Office)
CAPEC-118
,Â
CWE-200
,Â
ISO27001-A.18.1.3
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Insecure Frame (External)
Insecure Frame (External)
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
Insecure JSONP Endpoint
Insecure JSONP Endpoint
CWE-20
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A1
,Â
WASC-15
,Â
Low
Insecure Reflected Content
Insecure Reflected Content
CWE-16
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A1
,Â
WASC-15
,Â
Low
Insecure Transportation Security Protocol Supported (TLS 1.1)
Insecure Transportation Security Protocol Supported (TLS 1.1)
CAPEC-217
,Â
CWE-326
,Â
HIPAA-164.306
,Â
ISO27001-A.14.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.4
,Â
WASC-4
,Â
Low
Internal IP Address Disclosure
Internal IP Address Disclosure
CWE-200
,Â
ISO27001-A.18.1.4
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
Low
Internal Server Error
Internal Server Error
CWE-550
,Â
ISO27001-A.14.1.2
,Â
WASC-13
,Â
Low
Laravel Debug Mode Enabled
Laravel Debug Mode Enabled
CAPEC-214
,Â
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Laravel Environment Configuration File Detected
Laravel Environment Configuration File Detected
CWE-285
,Â
ISO27001-A.9.4.1
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
Microsoft IIS Log File Detected
Microsoft IIS Log File Detected
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
PCI v3.2-6.5.8
,Â
WASC-34
,Â
Low
Microsoft Outlook Personal Folders File (.pst) Found
Microsoft Outlook Personal Folders File (.pst) Found
CWE-284
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
PCI v3.2-6.5.8
,Â
WASC-2
,Â
Low
Misconfigured Access-Control-Allow-Origin Header
Misconfigured Access-Control-Allow-Origin Header
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.8
,Â
WASC-15
,Â
Low
Misconfigured Frame
Misconfigured Frame
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
Missing Content-Type Header
Missing Content-Type Header
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.7
,Â
WASC-15
,Â
Low
Missing X-Content-Type-Options Header
Missing X-Content-Type-Options Header
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
Open Redirection in POST method
Open Redirection in POST method
CWE-601
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A10
,Â
OWASP 2017-A5
,Â
WASC-38
,Â
Low
Out-of-date Component ({applicationName})
Out-of-date Component ({applicationName})
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
Passive Mixed Content over HTTPS
Passive Mixed Content over HTTPS
CWE-319
,Â
ISO27001-A.14.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
Low
Passive Web Backdoor Detected
Passive Web Backdoor Detected
CWE-507
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.12.2.1
,Â
OWASP 2017-A10
,Â
PCI v3.2-6.5.6
,Â
Low
Phishing by Navigating Browser Tabs
Phishing by Navigating Browser Tabs
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
PHP allow_url_fopen Is Enabled
PHP allow_url_fopen Is Enabled
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
PHP allow_url_include Is Enabled
PHP allow_url_include Is Enabled
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
PHP display_errors Is Enabled
PHP display_errors Is Enabled
CWE-211
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
phpinfo() Output Detected
phpinfo() Output Detected
CAPEC-346
,Â
CWE-213
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
WASC-13
,Â
Low
PHP open_basedir Is Not Configured
PHP open_basedir Is Not Configured
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Programming Error Message
Programming Error Message
CAPEC-118
,Â
CWE-210
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Programming Error Message (Ruby)
Programming Error Message (Ruby)
CAPEC-118
,Â
CWE-210
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Reflected File Download
Reflected File Download
CAPEC-375
,Â
CWE-840
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
PCI v3.2-6.5.1
,Â
WASC-42
,Â
Low
RoR Database Configuration File Detected
RoR Database Configuration File Detected
CWE-285
,Â
ISO27001-A.9.4.1
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
RoR Development Mode Enabled
RoR Development Mode Enabled
CAPEC-214
,Â
CWE-16
,Â
ISO27001-A.14.1.1
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Sensitive Pages Could Be Cached
Sensitive Pages Could Be Cached
CWE-525
,Â
Low
Social Security Number Disclosure
Social Security Number Disclosure
CAPEC-118
,Â
CWE-213
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.3
,Â
WASC-13
,Â
Low
Stack Trace Disclosure (Apache MyFaces)
Stack Trace Disclosure (Apache MyFaces)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (Apache Shiro)
Stack Trace Disclosure (Apache Shiro)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (ASP.NET)
Stack Trace Disclosure (ASP.NET)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (CakePHP Framework)
Stack Trace Disclosure (CakePHP Framework)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (CherryPy)
Stack Trace Disclosure (CherryPy)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (Grails)
Stack Trace Disclosure (Grails)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (GraphQL)
Stack Trace Disclosure (GraphQL)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (Node.js)
Stack Trace Disclosure (Node.js)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Stack Trace Disclosure (PHP)
Stack Trace Disclosure (PHP)
CAPEC-214
,Â
CWE-248
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.9.2.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Struts2 Development Mode Enabled
Struts2 Development Mode Enabled
CAPEC-214
,Â
CWE-16
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-14
,Â
Low
Subresource Integrity (SRI) Hash Invalid
Subresource Integrity (SRI) Hash Invalid
CWE-16
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
Low
TRACE/TRACK Method Detected
TRACE/TRACK Method Detected
CAPEC-107
,Â
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-14
,Â
Low
Unexpected Redirect Response Body (Two Responses)
Unexpected Redirect Response Body (Two Responses)
CWE-698
,Â
ISO27001-A.14.2.5
,Â
WASC-25
,Â
Low
User Controllable Cookie
User Controllable Cookie
CWE-20
,Â
ISO27001-A.14.2.5
,Â
WASC-20
,Â
Low
Username Disclosure (Microsoft SQL Server)
Username Disclosure (Microsoft SQL Server)
CAPEC-118
,Â
CWE-201
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.18.1.4
,Â
OWASP 2013-A5
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Username Disclosure (MySQL)
Username Disclosure (MySQL)
CAPEC-118
,Â
CWE-201
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.18.1.4
,Â
OWASP 2013-A5
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Version Disclosure (AbanteCart)
Version Disclosure (AbanteCart)
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
Version Disclosure (Ampache)
Version Disclosure (Ampache)
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
Version Disclosure (Angular)
Version Disclosure (Angular)
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
Version Disclosure (Angularjs)
Version Disclosure (Angularjs)
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
1