hse local report 172.16.1.48

Upload: tuyen-nguyen

Post on 07-Feb-2018

215 views

Category:

Documents


0 download

TRANSCRIPT

  • 7/21/2019 HSE Local Report 172.16.1.48

    1/3

    Acunetix Website Audit

    23 January, 2014

    Developer Report

    Generated by Acunetix WVS Reporter (v8.0 Build 20120704)

  • 7/21/2019 HSE Local Report 172.16.1.48

    2/3

    Scan of http://172.16.1.48:80/

    Scan information

    Scan details

    Starttime 1/22/2014 5:01:03 PM

    Finish time The scan was aborted by the user

    Scan time 16 hours, 2 minutesProfile Default

    Server information

    Responsive True

    Server banner Microsoft-IIS/8.0

    Server OS Windows

    Server technologies ASP.NET

    Threat level

    Acunetix Threat Level 3One or more high-severity type vulnerabilities have been discovered by the scanner. Amalicious user can exploit these vulnerabilities and compromise the backend databaseand/or deface your website.

    Alerts distribution

    High

    Medium

    Low

    Informational 22

    8

    15

    6

    51Total alerts found

    Alerts summary

    Cross Site Scripting (verified)

    Affects Variation

    6/MOC/Lists/LstMOCRequirement/DispForm.aspx

    Application error message

    Affects Variation

    6/

    4/_layouts/15/ScriptResx.ashx

    3/ScriptResource.axd

    2/WebResource.axd

    2Acunetix Website Audit

  • 7/21/2019 HSE Local Report 172.16.1.48

    3/3

    File upload

    Affects Variation

    1/_layouts/15/userdisp.aspx

    1/MOC/_layouts/15/userdisp.aspx

    1/MOC/Lists/LstMOCRequirement/DispForm.aspx

    1/MOC/Lists/LstMOCRequirement/NewForm.aspx

    1/Monitoring/_layouts/15/userdisp.aspx

    OPTIONS method is enabled

    Affects Variation

    2Web Server

    Session Cookie without Secure flag set

    Affects Variation

    1/

    Broken links

    Affects Variation

    1/_layouts/15/callto

    1/a

    1/Document

    1/MOC/_layouts/15/callto

    1/MOC/MOC/_catalogs/masterpage

    1/Monitoring/_layouts/15/callto

    1/Monitoring/Monitoring/_catalogs/masterpage

    1/ShareInfo/ShareInfo/_catalogs/masterpage

    1/Style%20Library/us-en/Core%20Styles/MetroStyle.css

    Microsoft Frontpage Configuration Information

    Affects Variation

    2/_vti_inf.html

    Unencrypted __VIEWSTATE parameter

    Affects Variation

    1/_layouts/15/error.aspx (92ebe9df59e7899073239dea50036fd7)

    1/_layouts/15/people.aspx (f7ae78efefe808b8c33fa1ba51a2f38d)

    1/MOC/_layouts/15/SubChoos.aspx (0564f591ef3594235396c97045c02964)

    1/MOC/_layouts/15/SubNew.aspx (fba24dde9177ddda01762e0fc66a9950)

    1/MOC/Lists/CodeManagerment/DispForm.aspx (547c7aa3423e4c1d53a4d20dec4fad27)

    1/MOC/Lists/LstMOCRequirement/NewForm.aspx (d6e7447753d6b7ee68373c5ea6449a83)

    1/MOC/Lists/Tasks/AllItems.aspx (8fcea39b01ea31bb5041f3c0d5913e42)

    1/MOC/MOCTemplate/Forms/AllItems.aspx (abc9b900f244cf038b89f4afe32f8748)

    1/Monitoring/_layouts/15/RecentWikiPages.aspx (a3d6a2629f5e8cfd8ff9895ec5732a8d)

    1/ShareInfo/_layouts/15/error.aspx (dc7b0deafd2830b9e6499edeada4bdec)

    1/ShareInfo/Pictures/Forms/Thumbnails.aspx (d29636f48e3863d321de3b8c3ca098e0)

    3Acunetix Website Audit