Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
XSS Vulnerability IW 15.2.23
#2
Anyone offer any advise please?

I should add I have now downloaded ZAP to test and struggling with it a bit.  I created a fresh basic IW app and did an initial scan and it comes back clean, but a second scan shows the XSS java attack.  Playing around with cookie options in various configurations does seem  to alter the results but inconsistently and I am confused.  Is there a better tool to use that works on SA and localhost?

I have tried latest build out of the box and not had any XSS reported but as I said above, my ZAP results seem inconsistent so not entirely sure if the latest build has fixed this or not.  has there been any changes from 15.2.23 that may have fixed it?  I looked and never noticed anything but I may have missed it.

Ultimately will move to latest build soon anyway.  Can I just simply upgrade IW then rebuild or do I need to do anything else such as opening up and resaving forms etc?

Cheers.
Reply


Messages In This Thread
RE: XSS Vulnerability IW 15.2.23 - by davidmcevoy@outlook.com - 09-07-2024, 08:47 AM
RE: XSS Vulnerability IW 15.2.23 - by joelcc - 09-10-2024, 04:13 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)