[Medium] Sub Resource Integrity Attribute Missing - "
SQL injection detected in parameter 'SQLMap confirmed SQLi!'
Redis Lua sandbox escape vulnerability CVE-2022-0543 allows RCE on Debian-packaged Redis.
CVE: CVE-2022-0543
缺少以下安全Header: X-Frame-Options (点击劫持防护), X-Content-Type-Options, Content-Security-Policy, Strict-Transport-Security (HSTS), X-XSS-Protection, Referrer-Policy, Permissions-Policy
CORS配置允许任意来源(*),可能导致敏感数据被恶意网站访问
💡 低优先级 (21个)
点击展开
- Cookie No HttpOnly Flag (zap)
- Cookie Without Secure Flag (zap)
- Cookie without SameSite Attribute (zap)
- Cross-Domain JavaScript Source File Inclusion (zap)
- Server Leaks Version Information via "Server" HTTP Response Header Field (zap)
- Strict-Transport-Security Header Not Set (zap)
- X-Content-Type-Options Header Missing (zap)
- Modern Web Application (zap)
- Re-examine Cache-control Directives (zap)
- Session Management Response Identified (zap)
- ...还有 11 个
🛡️ 快速修复
| Header | 建议值 |
| X-Frame-Options | DENY |
| Content-Security-Policy | default-src 'self' |
| X-Content-Type-Options | nosniff |
| Strict-Transport-Security | max-age=31536000 |