ziontavera / cyberchief-test-scan

0 stars 0 forks source link

Secure Pages Include Mixed Content (Including Scripts) #4

Open ziontavera opened 4 months ago

ziontavera commented 4 months ago

Workspace:

Default

Description:

The page includes mixed content, that is content accessed via HTTP instead of HTTPS.

Vulnerability Resolution:

A page that is available over SSL/TLS must be comprised completely of content which is transmitted over SSL/TLS.

The page must not contain any content that is transmitted over unencrypted HTTP.

This includes content from third party sites.

Evidence:

http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0

http://www.exampledomainnotinuse.org/mybeacon.gif

Affected Info:

tag=object codebase=http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0

tag=img src=http://www.exampledomainnotinuse.org/mybeacon.gif

Affected URL:

https://demo.testfire.net/index.jsp?content=inside_contact.htm

https://demo.testfire.net/index.jsp?content=inside_benefits.htm