Skip to content

Active scanner rules version 49

Choose a tag to compare

@zapbot zapbot released this 27 Oct 09:38
· 6598 commits to main since this release
4af19ca

Added

  • The following scan rules were added, having been promoted from Beta:
    • .env Information Leak
    • Cloud Metadata Attack
    • GET for POST
    • Heartbleed OpenSSL Vulnerability
    • Hidden File Finder
    • Padding Oracle
    • Remote Code Execution - CVE-2012-1823
    • Source Code Disclosure - CVE-2012-1823
    • SQL Injection - Hypersonic (Time Based)
    • SQL Injection - MsSQL (Time Based)
    • SQL Injection - MySQL (Time Based)
    • SQL Injection - Oracle (Time Based)
    • SQL Injection - PostgreSQL (Time Based)
    • SQL Injection - SQLite
    • Trace.axd Information Leak
    • User Agent Fuzzer
    • XSLT Injection
    • XXE

Changed

  • Update minimum ZAP version to 2.12.0.
  • Maintenance changes.
  • Rely on Network add-on to obtain more information about socket timeouts.