安全扫描警报列表(漏洞索引)
- 0Directory BrowsingMedium
- 2Private IP DisclosureLow
- 3-1Session ID in URL RewriteMedium
- 3-2Session ID in URL RewriteMedium
- 3-3Referer Exposes Session IDMedium
- 6-1Path TraversalHigh
- 6-2Path TraversalHigh
- 6-3Path TraversalHigh
- 6-4Path TraversalHigh
- 6-5Path TraversalHigh
- 7Remote File InclusionHigh
- 41Source Code Disclosure - Git High
- 42Source Code Disclosure - SVNMedium
- 43Source Code Disclosure - File InclusionHigh
- 10003Vulnerable JS LibraryMedium
- 10009In Page Banner Information LeakLow
- 10010Cookie No HttpOnly FlagLow
- 10011Cookie Without Secure FlagLow
- 10015Re-examine Cache-control DirectivesInformational
- 10017Cross-Domain JavaScript Source File InclusionLow
- 10019-1Content-Type Header MissingInformational
- 10019-2Content-Type Header EmptyInformational
- 10020-1Missing Anti-clickjacking HeaderMedium
- 10020-2Multiple X-Frame-Options Header EntriesMedium
- 10020-3X-Frame-Options Defined via META (Non-compliant with Spec)Medium
- 10020-4X-Frame-Options Setting MalformedMedium
- 10021X-Content-Type-Options Header MissingLow
- 10023Information Disclosure - Debug Error MessagesLow
- 10024Information Disclosure - Sensitive Information in URLInformational
- 10025Information Disclosure - Sensitive Information in HTTP Referrer HeaderInformational
- 10026HTTP Parameter OverrideMedium
- 10027Information Disclosure - Suspicious CommentsInformational
- 10028Open RedirectHigh
- 10029Cookie PoisoningInformational
- 10030User Controllable CharsetInformational
- 10031User Controllable HTML Element Attribute (Potential XSS)Informational
- 10032-1Potential IP Addresses Found in the ViewstateMedium
- 10032-2Emails Found in the ViewstateMedium
- 10032-3Old Asp.Net Version in UseLow
- 10032-4Viewstate without MAC Signature (Unsure)High
- 10032-5Viewstate without MAC Signature (Sure)High
- 10032-6Split Viewstate in UseInformational
- 10033Directory BrowsingMedium
- 10034Heartbleed OpenSSL Vulnerability (Indicative)High
- 10035-1Strict-Transport-Security Header Not SetLow
- 10035-2Strict-Transport-Security DisabledLow
- 10035-3Strict-Transport-Security Multiple Header Entries (Non-compliant with Spec)Low
- 10035-4Strict-Transport-Security Header on Plain HTTP ResponseInformational
- 10035-5Strict-Transport-Security Missing Max-Age (Non-compliant with Spec)Low
- 10035-6Strict-Transport-Security Defined via META (Non-compliant with Spec)Low
- 10035-7Strict-Transport-Security Max-Age Malformed (Non-compliant with Spec)Low
- 10035-8Strict-Transport-Security Malformed Content (Non-compliant with Spec)Low
- 10036-1Server Leaks its Webserver Application via "Server" HTTP Response Header FieldInformational
- 10036-2Server Leaks Version Information via "Server" HTTP Response Header FieldLow
- 10037Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)Low
- 10038-1Content Security Policy (CSP) Header Not SetMedium
- 10038-2Obsolete Content Security Policy (CSP) Header FoundInformational
- 10038-3Content Security Policy (CSP) Report-Only Header FoundInformational
- 10039X-Backend-Server Header Information LeakLow
- 10040Secure Pages Include Mixed ContentLow
- 10041HTTP to HTTPS Insecure Transition in Form PostMedium
- 10042HTTPS to HTTP Insecure Transition in Form PostMedium
- 10043User Controllable JavaScript Event (XSS)Informational
- 10044-1Big Redirect Detected (Potential Sensitive Information Leak)Low
- 10044-2Multiple HREFs Redirect Detected (Potential Sensitive Information Leak)Low
- 10045-1Source Code Disclosure - /WEB-INF FolderHigh
- 10045-2Properties File Disclosure - /WEB-INF folderHigh
- 10047HTTPS Content Available via HTTPLow
- 10048-1Remote Code Execution - Shell ShockHigh
- 10048-2Remote Code Execution - Shell ShockHigh
- 10049-1Non-Storable ContentInformational
- 10049-2Storable but Non-Cacheable ContentInformational
- 10049-3Storable and Cacheable ContentInformational
- 10050-1Retrieved from CacheInformational
- 10050-2Retrieved from CacheInformational
- 10051Relative Path ConfusionMedium
- 10052X-ChromeLogger-Data (XCOLD) Header Information LeakMedium
- 10053Apache Range Header DoS (CVE-2011-3192)Medium
- 10054-1Cookie without SameSite AttributeLow
- 10054-2Cookie with SameSite Attribute NoneLow
- 10054-3Cookie with Invalid SameSite AttributeLow
- 10055-1CSP: X-Content-Security-PolicyLow
- 10055-2CSP: X-WebKit-CSPLow
- 10055-3CSP: NoticesLow
- 10055-4CSP: Wildcard DirectiveMedium
- 10055-5CSP: script-src unsafe-inlineMedium
- 10055-6CSP: style-src unsafe-inlineMedium
- 10055-7CSP: script-src unsafe-hashesMedium
- 10055-8CSP: style-src unsafe-hashesMedium
- 10055-9CSP: Malformed Policy (Non-ASCII)Medium
- 10055-10CSP: script-src unsafe-evalMedium
- 10055-11CSP: Meta Policy Invalid DirectiveMedium
- 10055-12CSP: Header & MetaInformational
- 10056X-Debug-Token Information LeakLow
- 10057Username Hash FoundInformational
- 10058GET for POSTInformational
- 10061X-AspNet-Version Response HeaderLow
- 10062PII DisclosureHigh
- 10063-1Permissions Policy Header Not SetLow
- 10063-2Deprecated Feature Policy Header SetLow
- 10094-1ASP.NET ViewState DisclosureInformational
- 10094-2ASP.NET ViewState IntegrityHigh
- 10094-3Base64 DisclosureInformational
- 10095Backup File DisclosureMedium
- 10096Timestamp Disclosure - UnixLow
- 10097Hash Disclosure - MD4 / MD5Low
- 10098Cross-Domain MisconfigurationMedium
- 10099Source Code Disclosure - PHPMedium
- 10101Access Control Issue - Improper AuthenticationHigh
- 10102Access Control Issue - Improper AuthorizationHigh
- 10103Image Exposes Location or Privacy DataInformational
- 10104User Agent FuzzerInformational
- 10105-1Authentication Credentials CapturedMedium
- 10105-2Weak Authentication MethodMedium
- 10106HTTP Only SiteMedium
- 10107Httpoxy - Proxy Header MisuseHigh
- 10108Reverse TabnabbingMedium
- 10109Modern Web ApplicationInformational
- 10110Dangerous JS FunctionsLow
- 10111Authentication Request IdentifiedInformational
- 10112Session Management Response IdentifiedInformational
- 10113Verification Request IdentifiedInformational
- 10202Absence of Anti-CSRF TokensMedium
- 20012Anti-CSRF Tokens CheckMedium
- 20014HTTP Parameter PollutionInformational
- 20015Heartbleed OpenSSL VulnerabilityHigh
- 20016-1Cross-Domain Misconfiguration - Adobe - ReadHigh
- 20016-2Cross-Domain Misconfiguration - Adobe - SendHigh
- 20016-3Cross-Domain Misconfiguration - SilverlightHigh
- 20017Source Code Disclosure - CVE-2012-1823High
- 20018Remote Code Execution - CVE-2012-1823High
- 20019-1External RedirectHigh
- 20019-2External RedirectHigh
- 20019-3External RedirectHigh
- 20019-4External RedirectHigh
- 30001Buffer OverflowMedium
- 30002Format String ErrorMedium
- 30003Integer Overflow ErrorMedium
- 40003CRLF InjectionMedium
- 40008Parameter TamperingMedium
- 40009Server Side IncludeHigh
- 40012Cross Site Scripting (Reflected)High
- 40013Session FixationHigh
- 40014Cross Site Scripting (Persistent)High
- 40015LDAP InjectionHigh
- 40016Cross Site Scripting (Persistent) - PrimeInformational
- 40017Cross Site Scripting (Persistent) - SpiderInformational
- 40018SQL InjectionHigh
- 40019SQL Injection - MySQLHigh
- 40020SQL Injection - Hypersonic SQLHigh
- 40021SQL Injection - OracleHigh
- 40022SQL Injection - PostgreSQLHigh
- 40023Possible Username EnumerationInformational
- 40024SQL Injection - SQLiteHigh
- 40025Proxy DisclosureMedium
- 40026Cross Site Scripting (DOM Based)High
- 40027SQL Injection - MsSQLHigh
- 40028ELMAH Information LeakMedium
- 40029Trace.axd Information LeakMedium
- 40031Out of Band XSSHigh
- 40032.htaccess Information LeakMedium
- 40033NoSQL Injection - MongoDBHigh
- 40034.env Information LeakMedium
- 40035Hidden File FoundMedium
- 40036JWT Scan RuleMedium
- 40038Bypassing 403Medium
- 40039Web Cache DeceptionMedium
- 40040-1CORS HeaderInformational
- 40040-2CORS MisconfigurationMedium
- 40040-3CORS MisconfigurationHigh
- 40041File UploadMedium
- 40042Spring Actuator Information LeakMedium
- 40043-1Log4Shell (CVE-2021-44228)High
- 40043-2Log4Shell (CVE-2021-45046)High
- 40044Exponential Entity Expansion (Billion Laughs Attack)Medium
- 40045Spring4ShellHigh
- 40046Server Side Request ForgeryHigh
- 40047Text4shell (CVE-2022-42889)High
- 50007-1GraphQL Endpoint Supports IntrospectionInformational
- 50007-2GraphQL Server Implementation IdentifiedInformational
- 90001Insecure JSF ViewStateMedium
- 90002Java Serialization ObjectMedium
- 90003Sub Resource Integrity Attribute MissingMedium
- 90004-1Insufficient Site Isolation Against Spectre VulnerabilityLow
- 90004-2Insufficient Site Isolation Against Spectre VulnerabilityLow
- 90004-3Insufficient Site Isolation Against Spectre VulnerabilityLow
- 90005-1Sec-Fetch-Site Header is MissingInformational
- 90005-2Sec-Fetch-Mode Header is MissingInformational
- 90005-3Sec-Fetch-Dest Header is MissingInformational
- 90005-4Sec-Fetch-User Header is MissingInformational
- 90005-5Sec-Fetch-Site Header Has an Invalid ValueInformational
- 90005-6Sec-Fetch-Mode Header Has an Invalid ValueInformational
- 90005-7Sec-Fetch-Dest Header Has an Invalid ValueInformational
- 90005-8Sec-Fetch-User Header Has an Invalid ValueInformational
- 90011Charset MismatchInformational
- 90017XSLT InjectionMedium
- 90018Advanced SQL InjectionHigh
- 90019-1Server Side Code Injection - PHP Code InjectionHigh
- 90019-2Server Side Code Injection - ASP Code InjectionHigh
- 90020Remote OS Command InjectionHigh
- 90021XPath InjectionHigh
- 90022Application Error DisclosureMedium
- 90023XML External Entity AttackHigh
- 90024Generic Padding OracleHigh
- 90025Expression Language InjectionHigh
- 90026SOAP Action SpoofingHigh
- 90027Cookie Slack DetectorInformational
- 90028Insecure HTTP MethodMedium
- 90029SOAP XML InjectionHigh
- 90033Loosely Scoped CookieInformational
- 90034Cloud Metadata Potentially ExposedHigh
- 90035Server Side Template InjectionHigh
- 90036Server Side Template Injection (Blind)High
- 90039NoSQL Injection - MongoDB (Time Based)High
- 110001Application Error Disclosure via WebSocketsMedium
- 110002Base64 Disclosure in WebSocket messageInformational
- 110003Information Disclosure - Debug Error Messages via WebSocketLow
- 110004Email address found in WebSocket messageInformational
- 110005Personally Identifiable Information via WebSocketHigh
- 110006Private IP Disclosure via WebSocketLow
- 110007Username Hash Found in WebSocket messageInformational
- 110008Information Disclosure - Suspicious Comments in XML via WebSocketInformational
- 110009Full Path DisclosureLow
- 120000-1Information Disclosure - Information in Browser localStorageInformational
- 120000-2Information Disclosure - Information in Browser sessionStorageInformational
- 120001-1Information Disclosure - Sensitive Information in Browser localStorageLow
- 120001-2Information Disclosure - Sensitive Information in Browser sessionStorageLow
- 120002-1Information Disclosure - JWT in Browser localStorageMedium
- 120002-2Information Disclosure - JWT in Browser sessionStorageInformational
- 1
- 2
- 3
- 4
- 5
- 6
- 23
理解安全扫描警报:3 个关键问题
此页面上的警报代表什么
这里列出的每一条警报都来自网站安全扫描,描述扫描器在站点上发现的一处薄弱点——从跨站脚本(XSS)、SQL 注入,到缺少安全响应头和 SSL/TLS 配置不当。高危警报意味着攻击者很可能直接利用,中低危警报则提示加固机会。浏览完整列表,可以直观了解一个网站最容易被攻击的位置。
如何按风险等级优先处理警报
先从高危项开始,因为它们最容易转化为实际危害——存储型或反射型 XSS、SQL 注入、凭据泄露。中危项(缺少防点击劫持头、缓存控制配置不当)随后安排,最后处理低危的信息泄露(版本号暴露、目录浏览)。按风险顺序修复,投入与真实暴露面成正比。
哪些警报可以自己修复
很多常见警报属于配置修复而非代码改动。添加 Content-Security-Policy、X-Frame-Options、X-Content-Type-Options 等安全响应头,通常只需在服务器或 CDN 配置中写几行。目录浏览和信息泄露警报往往通过简单的访问规则即可关闭。SQL 注入等应用层问题需要开发人员处理,可参考每条警报页面的修复说明。
安全扫描警报是行动信号,不是最终判决。从最高风险项开始逐项处理,先修复服务器配置能解决的问题,再重新扫描确认每一项已消除。如果站点已出现异常文件或未知后门,请立即隔离网站、检查访问日志并清除恶意代码,防止影响进一步扩散。
常见问题(FAQ)
安全扫描器会按风险等级和类别对警报分组。常见类别包括 SQL 注入等注入类漏洞、跨站脚本(XSS)、缺少安全响应头、SSL/TLS 配置错误、信息泄露以及目录浏览。本页面每条警报都标注了风险等级,方便区分紧急项和加固项。
警报意味着扫描器在您的站点上检测到攻击者可能利用的薄弱点。它是一个需要调查和修复的信号,不代表网站已被入侵。按风险等级逐项处理后,重新扫描确认每项都已解决。
大多数安全响应头警报属于配置修复。在 Web 服务器或 CDN 配置中添加推荐的头——例如 Content-Security-Policy、X-Frame-Options、X-Content-Type-Options 或 Referrer-Policy——然后重新扫描确认已生效。