Information Disclosure - Suspicious Comments in XML via WebSocket
- Risk:
Informational
- Type:
- WebSocket Passive
- CWE:
- CWE-200
- Summary
The response appears to contain suspicious comments which may help an attacker.
- Solution
Remove all comments that return information that may help an attacker and fix any underlying problems they refer to.
Oracle denies breach after hacker claims theft of 6 million data records
Microsoft confirms it's killing off Skype in May, after 14 years
CosmicSting flaw impacts 75% of Adobe Commerce, Magento sites
CrushFTP: Patch critical vulnerability ASAP! (CVE-2025-2825)
NAKIVO Backup & Replication vulnerability exploited by attackers (CVE-2024-48248)
New SuperBlack ransomware exploits Fortinet auth bypass flaws
Microsoft Trusted Signing service abused to code-sign malware
Critical Next.js auth bypass vulnerability opens web apps to compromise (CVE-2025-29927)
Oracle customers confirm data stolen in alleged cloud breach is valid
CVE-2020-29574 CyberoamOS (CROS) SQL Injection Vulnerability
CVE-2024-49035 Microsoft Partner Center Improper Access Control Vulnerability
CVE-2025-22224 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
CVE-2022-43939 Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
CVE-2024-20953 Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
CVE-2024-41710 Mitel SIP Phones Argument Injection Vulnerability
CVE-2025-0111 Palo Alto Networks PAN-OS File Read Vulnerability
CVE-2022-43769 Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
CVE-2018-8639 Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
CVE-2018-19410 Paessler PRTG Network Monitor Local File Inclusion Vulnerability
Free online web security scanner