Skip to content

Active scanner rules version 60

Choose a tag to compare

@zapbot zapbot released this 16 Jan 12:13
· 4642 commits to main since this release
634bc1b

Changed

  • Leave data empty instead of adding "N/A" for the scan rules:
    • Cross Site Scripting (Persistent) - Prime
    • Cross Site Scripting (Persistent) - Spider
  • Update reference for Server Side Code Injection (Issue 8262).
  • Now depends on minimum Common Library version 1.21.0.

Fixed

  • Threshold handling in the Hidden File Finder scan rule.
  • Improved the following scan rules by using time-based linear regression tests:
    • Server Side Template Injection (Blind)
    • SQL Injection - Hypersonic SQL
    • SQL Injection - MsSQL
    • SQL Injection - MySQL

Added

  • Help entry for the Spring Actuators scan rule (missed during previous promotion).
  • Website alert links to the help page (Issue 8189).
  • The following scan rules now include example alert functionality for documentation generation purposes (Issue 6119) and in some cases updated references (Issue 8262).
    • CRLF Injection
    • Remote OS Command Injection
    • GET for POST
    • ELMAH Information Leak
    • .env Information Leak
    • .htaccess Information Leak
    • Trace.axd Information Leak