<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-204 on ZAP</title>
    <link>/alerttags/cwe-204/</link>
    <description>Recent content in CWE-204 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-204/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Possible Username Enumeration</title>
      <link>/docs/alerts/40023/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40023/</guid>
      <description>&lt;p&gt;It may be possible to enumerate usernames, based on differing HTTP responses when valid and invalid usernames are provided. This would greatly increase the probability of success of password brute-forcing attacks against the system. Note that false positives may sometimes be minimised by increasing the &amp;lsquo;Attack Strength&amp;rsquo; Option in ZAP. Please manually check the &amp;lsquo;Other Info&amp;rsquo; field to confirm if this is actually an issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Proxy Disclosure</title>
      <link>/docs/alerts/40025-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40025-1/</guid>
      <description>&lt;p&gt;1 proxy server(s) were detected or fingerprinted. This information helps a potential attacker to determine&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A list of targets for an attack against the application.&lt;/li&gt;&#xA;&lt;li&gt;Potential vulnerabilities on the proxy servers that service the application.&lt;/li&gt;&#xA;&lt;li&gt;The presence or absence of any proxy-based components that might cause attacks against the application to be detected, prevented, or mitigated.&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Proxy Disclosure</title>
      <link>/docs/alerts/40025-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40025-2/</guid>
      <description>&lt;p&gt;1 proxy server(s) were detected or fingerprinted. This information helps a potential attacker to determine&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A list of targets for an attack against the application.&lt;/li&gt;&#xA;&lt;li&gt;Potential vulnerabilities on the proxy servers that service the application.&lt;/li&gt;&#xA;&lt;li&gt;The presence or absence of any proxy-based components that might cause attacks against the application to be detected, prevented, or mitigated.&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
  </channel>
</rss>
