Alert Tag: POLICY_DEV_STD

POLICY_DEV_STD

All of the alerts which use this tag:
ID Alert Status Risk Type
3-1 Session ID in URL Rewrite release Medium Passive
3-2 Session ID in URL Rewrite release Medium Passive
3-3 Referer Exposes Session ID release Medium Passive
6-1 Path Traversal release High Active
6-2 Path Traversal release High Active
6-3 Path Traversal release High Active
6-4 Path Traversal release High Active
6-5 Path Traversal release High Active
7 Remote File Inclusion release High Active
10003 Vulnerable JS Library release Medium Passive
10010 Cookie No HttpOnly Flag release Low Passive
10011 Cookie Without Secure Flag release Low Passive
10017 Cross-Domain JavaScript Source File Inclusion release Low Passive
10024 Information Disclosure - Sensitive Information in URL release Informational Passive
10025 Information Disclosure - Sensitive Information in HTTP Referrer Header release Informational Passive
10026 HTTP Parameter Override beta Medium Passive
10028 Off-site Redirect release High Passive
10029 Cookie Poisoning release Informational Passive
10040 Secure Pages Include Mixed Content release Low Passive
10041 HTTP to HTTPS Insecure Transition in Form Post release Medium Passive
10042 HTTPS to HTTP Insecure Transition in Form Post release Medium Passive
10054-1 Cookie without SameSite Attribute release Low Passive
10054-2 Cookie with SameSite Attribute None release Low Passive
10054-3 Cookie with Invalid SameSite Attribute release Low Passive
10055-1 CSP: X-Content-Security-Policy release Low Passive
10055-2 CSP: X-WebKit-CSP release Low Passive
10055-3 CSP: Notices release Low Passive
10055-4 CSP: Wildcard Directive release Medium Passive
10055-5 CSP: script-src unsafe-inline release Medium Passive
10055-6 CSP: style-src unsafe-inline release Medium Passive
10055-7 CSP: script-src unsafe-hashes release Medium Passive
10055-8 CSP: style-src unsafe-hashes release Medium Passive
10055-9 CSP: Malformed Policy (Non-ASCII) release Medium Passive
10055-10 CSP: script-src unsafe-eval release Medium Passive
10055-11 CSP: Meta Policy Invalid Directive release Medium Passive
10055-12 CSP: Header & Meta release Informational Passive
10055-13 CSP: Failure to Define Directive with No Fallback release Medium Passive
10099 Source Code Disclosure - PHP beta Medium Passive
10105-1 Authentication Credentials Captured release Medium Passive
10105-2 Weak Authentication Method release Medium Passive
10108 Reverse Tabnabbing release Medium Passive
10109 Modern Web Application release Informational Passive
10115-1 Script Served From Malicious Domain (polyfill) release High Passive
10115-2 Script Served From Malicious Domain (polyfill) release High Passive
10202 Absence of Anti-CSRF Tokens release Medium Passive
20019-1 External Redirect release High Active
20019-2 External Redirect release High Active
20019-3 External Redirect release High Active
20019-4 External Redirect release High Active
40009 Server Side Include release High Active
40012 Cross Site Scripting (Reflected) release High Active
40018 SQL Injection release High Active
40048 Remote Code Execution (React2Shell) release High Active
90003 Sub Resource Integrity Attribute Missing release Medium Passive
90017 XSLT Injection release Medium Active
90020 Remote OS Command Injection release High Active
90021 XPath Injection release High Active
90023 XML External Entity Attack release High Active
90026 SOAP Action Spoofing beta High Active
90029 SOAP XML Injection beta High Active
90033 Loosely Scoped Cookie release Informational Passive
90035 Server Side Template Injection release High Active
90037 Remote OS Command Injection (Time Based) release High Active
110009 Full Path Disclosure alpha Low Passive