Skip to content

Active scanner rules (beta) version 27

Choose a tag to compare

@github-actions github-actions released this 16 Dec 15:48
ac1e066

Added

  • The following scan rules were promoted from Alpha to Beta:
    • Apache Range Header DoS
    • Cookie Slack Detector
    • ELMAH Information Leak
    • GET for POST
    • .htaccess Information Leak
    • HTTP Only Site
    • Httpoxy - Proxy Header Misuse
    • HTTPS Content Available via HTTP
    • Proxy Disclosure
    • Relative Path Confusion
    • Source Code Disclosure - File Inclusion
    • Source Code Disclosure - Git
    • SQL Injection - MsSQL
    • SQL Injection - SQLite
    • Trace.axd Information Leak
    • User Agent Fuzzer

Changed

  • Add dependency on Custom Payloads add-on.
  • Fixed ArrayIndexOutOfBoundsException issue in XML External Entity Attack scan rule.
    • Now removes original XML header in "Local File Reflection Attack".
  • Maintenance changes.
  • Update minimum ZAP version to 2.8.0.
  • Elmah scan rule updated to include a response content check, and vary alert confidence values accordingly.