Skip to content

Active scanner rules version 50

Choose a tag to compare

@zapbot zapbot released this 13 Dec 10:41
· 6376 commits to main since this release
15263b3

Changed

  • The Directory Browsing scan rule now includes example alert functionality for documentation generation purposes (Issue 6119).
  • Use lower case HTTP field names for compatibility with HTTP/2.
  • Maintenance changes.

Fixed

  • False positive in case of javascript: protocol xss attacks, when attack payload is modified by the application (Issue 6013).
  • Preserve the HTTP version in the scan rules:

Added

  • The Hidden File Finder scan rule will now also check for "/_wpeprivate/config.json".