Skip to content

triage sql injection#2

Open
cx-sean-casey wants to merge 1 commit intomasterfrom
triage2
Open

triage sql injection#2
cx-sean-casey wants to merge 1 commit intomasterfrom
triage2

Conversation

@cx-sean-casey
Copy link
Owner

No description provided.

@cx-sean-casey
Copy link
Owner Author

cx-sean-casey commented Feb 26, 2025

Logo
Checkmarx One – Scan Summary & Details5798ec48-4b0d-4d86-bb53-83f028f23e89

New Issues (3)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH Reflected_XSS /WebGoat/WebGoatCoins/ProductDetails.aspx: 19
detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 19 of /WebGoat/WebGoatCoins/ProductDetails.aspx. This ...
Attack Vector
HIGH Reflected_XSS /WebGoat/WebGoatCoins/CustomerLogin.aspx: 9
detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 9 of /WebGoat/WebGoatCoins/CustomerLogin.aspx. This un...
Attack Vector
MEDIUM Missing_HSTS_Header /WebGoat/Resources/Master-Pages/Site.Master: 28
detailsThe web-application does not define an HSTS header, leaving it vulnerable to attack.
Attack Vector
Fixed Issues (218)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 357

More results are available on the CxOne platform

Policy Management Violations (1)

Policy Name: test3
  • Rule Name: no highs
    Scanner: SAST
    Entity: Vulnerability
    Conditions(s): High > 1

    Severity Issue Source File / Package Checkmarx Insight
    HIGH HttpOnly_Cookie_Flag_Not_Set_In_Config /WebGoat/Web.config: 45
    detailsThe /WebGoat/Web.config application configuration file, at line 45, does not define sensitive application cookies with the "httpOnly" flag, which c...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/ProductDetails.aspx: 19
    detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 19 of /WebGoat/WebGoatCoins/ProductDetails.aspx. This ...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/CustomerLogin.aspx: 9
    detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 9 of /WebGoat/WebGoatCoins/CustomerLogin.aspx. This un...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/UploadPathManipulation.aspx.cs: 26
    detailsThe method btnUpload_Click embeds untrusted data in generated output with Text, at line 26 of /WebGoat/Content/UploadPathManipulation.aspx.cs. This...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/Orders.aspx.cs: 114
    detailsThe method GridView1_RowDataBound embeds untrusted data in generated output with Text, at line 114 of /WebGoat/WebGoatCoins/Orders.aspx.cs. This un...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/HeaderInjection.aspx.cs: 33
    detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 33 of /WebGoat/Content/HeaderInjection.aspx.cs. This untrusted da...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/ReflectedXSS.aspx.cs: 20
    detailsThe method LoadCity embeds untrusted data in generated output with Text, at line 26 of /WebGoat/Content/ReflectedXSS.aspx.cs. This untrusted data i...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/PathManipulation.aspx.cs: 33
    detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 43 of /WebGoat/Content/PathManipulation.aspx.cs. This untrusted d...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/Orders.aspx.cs: 62
    detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 83 of /WebGoat/WebGoatCoins/Orders.aspx.cs. This untrusted data i...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/SQLInjectionDiscovery.aspx.cs: 27
    detailsThe method btnFind_Click embeds untrusted data in generated output with Text, at line 30 of /WebGoat/Content/SQLInjectionDiscovery.aspx.cs. This un...
    Attack Vector
    HIGH XPath_Injection /WebGoat/Content/XPathInjection.aspx.cs: 20
    detailsThe application's FindSalesPerson method constructs an XPath query, for navigating an XML document. The XPath query is created with BinaryExpr, at ...
    Attack Vector

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant