- Site: https://py-sqli.onrender.com
New Alerts
- Cross Site Scripting (DOM Based) [40026] total: 4:
- [https://py-sqli.onrender.com/xss-demo#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)
- [https://py-sqli.onrender.com/xss-demo?search=ZAP#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo?search=ZAP#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)
- [https://py-sqli.onrender.com/xss-demo#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)
- [https://py-sqli.onrender.com/xss-demo?search=ZAP#jaVasCript:/-/
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo?search=ZAP#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)
- Cross Site Scripting (Reflected) [40012] total: 2:
- Remote Code Execution - Shell Shock [10048] total: 1:
- Remote OS Command Injection [90020] total: 1:
- Remote OS Command Injection (Time Based) [90037] total: 1:
- SQL Injection [40018] total: 1:
- Absence of Anti-CSRF Tokens [10202] total: 8:
- Anti-CSRF Tokens Check [20012] total: 5:
- Content Security Policy (CSP) Header Not Set [10038] total: 11:
- Missing Anti-clickjacking Header [10020] total: 11:
- Proxy Disclosure [40025] total: 24:
- Sub Resource Integrity Attribute Missing [90003] total: 11:
- Cookie Slack Detector [90027] total: 19:
- Cookie Without Secure Flag [10011] total: 7:
- Cookie without SameSite Attribute [10054] total: 7:
- Cross-Domain JavaScript Source File Inclusion [10017] total: 11:
- Dangerous JS Functions [10110] total: 4:
- Insufficient Site Isolation Against Spectre Vulnerability [90004] total: 12:
- Permissions Policy Header Not Set [10063] total: 11:
- Private IP Disclosure [2] total: 1:
- Strict-Transport-Security Header Not Set [10035] total: 11:
- X-Content-Type-Options Header Missing [10021] total: 11:
- Authentication Request Identified [10111] total: 1:
- Cookie Slack Detector [90027] total: 5:
- Modern Web Application [10109] total: 6:
- Non-Storable Content [10049] total: 4:
- Re-examine Cache-control Directives [10015] total: 8:
- Session Management Response Identified [10112] total: 7:
- Storable and Cacheable Content [10049] total: 7:
- User Agent Fuzzer [10104] total: 132:
View the following link to download the report.
RunnerID:18904214700
ZAP by Checkmarx
New Alerts
/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo?search=ZAP#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)/*\/'/"/**/(/* /oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e](https://py-sqli.onrender.com/xss-demo?search=ZAP#jaVasCript:/*-/*`/*\`/*'/*"/**/(/ */oNcliCk=alert(5397) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(5397)//>\x3e)View the following link to download the report.
RunnerID:18904214700
ZAP by Checkmarx