还剩9页未读,继续阅读
本资源只提供10页预览,全部文档请下载后查看!喜欢就下载吧,查找使用更方便
文本内容:
MatriXay Web应用安全评估报告I旦亘信息DAS-security旦全卬国应用安全和数据库安全的领航者[WebScan Version:V
6.
0.
1.10,Engine Version:V
6.
1.79,Policy Version:V
6.
1.100]URL http://
10.
10.
1.43:8080/master/static/lib/弱点PUT,DELETE等级低危URLhttp://
10.
10.
1.43:8080/master/static/lib/jquery-backstretc h/弱点PUT,DELETE等级低危URLhttp://
10.
10.
1.43:8080/master/static/1ib/jquery.uniform/di st/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/lib/metronic/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/lib/jquery.uniform/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/plugins/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/my/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/lib/amazeui/i/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/lib/amazeui/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/css/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/plugins/layer/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/index/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/lib/amazeui/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/lib/amazeui/i/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/css/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/lib/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/index/弱点PUT,DELETE等级低危URLhttp://
10.
10.
1.43:8080/master/view/static/lib/jquery,unifo rm/弱点PUT,DELETE等级低危http://
10.
10.
1.43:8080/master/view/static/lib/jquery.unifoURLrm/di st/弱点PUT,DELETE等级低危http://
10.
10.
1.43:8080/master/view/static/lib/jquery-backsURLtretch/弱点PUT,DELETE等级低危http://
10.
10.
1.43:8080/master/view/static/lib/metronic/scrURLipts/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/js/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/lib/metronic/弱点PUT,DELETE等级低危URLhttp://
10.
10.
1.43:8080/master/view/static/js/plugins/layer/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/js/plugins/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/image/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/view/static/js/my/弱点PUT,DELETE等级低危URLhttp://
10.
10.
1.43:8080/master/static/js/plugins/layer/skin/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/text/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/application/弱点PUT,DELETE等级低危URLhttp://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/global/弱点PUT,DELETE等级低危http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/URLglobal/img/弱点PUT,DELETE等级低危http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/URLglobal/css/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/my/static/img/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/my/static/弱点PUT,DELETE等级低危http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/URLglobal/plugins/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/my/static/img/bg/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/css/patterns/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/echarts/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/echarts/img/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/img/弱点PUT,DELETE等级低危http://
10.
10.
1.43:8080/master/static/js/plugins/layer/skinURL/default/弱点PUT,DELETE等级低危基于连接的登录请求
2.
1.
4.
2.
2.HTTPURL http://
10.
10.
1.43:8080/master/view/loginUI.shtml弱点uAccount=testuPassword=test=test等级低危参考标准
3.漏洞危害分级标准
3.
1.目前定义有五类危害等级,危害等级定义依据为紧急
3.
1.
1.可以直接被利用的漏洞,且利用难度较低被攻击之后可能对网站或服务器的正常运行造成严重影响,或对用户财产及个人信息造成重大损失局危
3.
1.
2.被利用之后,造成的影响较大,但直接利用难度较高的漏洞或本身无法直接攻击,但能为进一步攻击造成极大便利的漏洞中危
3.
1.
3.利用难度极高,或满足严格条件才能实现攻击的漏洞或漏洞本身无法被直接攻击,但能为进一步攻击起较大帮助作用的漏洞.低危
3.
1.4无法直接实现攻击,但提供的信息可能让攻击者更容易找到其他安全漏洞.信息
3.L5本身对网站安全没有直接影响,提供的信息可能为攻击者提供少量帮助,或可用于其他手段的攻击,如社工等综述.1本报告共检查了1个网站,共访问了100个URL,完成了29300次测试测试策略集
1.
1.制定系统默认策略网站统计列表
1.
2.本报告包含1个web站点,通过对其进行web安全检测具体列表如下:网站名称服务器类型安全值漏洞个数紧急漏洞个数备注
10.
10.
1.43Apache-Coyote/
1.189950网络不稳定注网络因素问题,可能会影响被扫描网站扫描结果的准确性;网站漏洞详细报告.2详细才艮告
3.
1.
10.
10.
1.43:8080扫描信息列表
2.
1.1,名称内容项目名称数据交换监控平台扫描对象
10.
10.
1.43主机端口8080开始时间2019-07-2916:05:33结束时间2019-07-2916:42:43扫描用时(时:分:秒)0:37:10服务器信息Apache-Coyote/
1.1服务器时间2019-07-2916:05:29协议http域名
10.
10.
1.43已访问URL100URL总数100网站安全值89漏洞个数95按照等级统计
2.
1.2,URL http://
10.
10.
1.43:8080/master/view/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/1ib/弱点PUT,DELETE等级中危URLhttp://
10.
10.
1.43:8080/master/static/lib/jquery-backstretc h/弱点PUT,DELETE等级中危URLhttp://
10.
10.
1.43:8080/master/static/lib/jquery.uniform/di st/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/lib/metronic/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/1ib/jquery.uniform/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/plugins/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/my/弱点PUT,DELETE漏洞详细信息列表
2.
1.
4.中危漏洞
2.
1.
4.
1.按照名称统计
2.
1.
3.启用了不安全的方法
2.
1.
4.
1.
1.HTTP等级中危URL http://
10.
10.
1.43:8080/master/static/1ib/amazeui/i/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/lib/amazeui/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/css/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/plugins/layer/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/index/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/lib/amazeui/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/lib/amazeui/i/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/css/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/lib/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/index/弱点PUT,DELETE等级中危URLhttp://
10.
10.
1.43:8080/master/view/static/1ib/jquery.unifo rm/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/view/static/1ib/jquery.unifoURLrm/dist/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/view/static/1ib/jquery-backsURLtretch/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/view/static/lib/metronic/scrURLipts/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/js/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/lib/metronic/弱点PUT,DELETE等级中危URLhttp://
10.
10.
1.43:8080/master/view/static/js/plugins/layer/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/js/plugins/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/image/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/view/static/js/my/弱点PUT,DELETE等级中危URLhttp://
10.
10.
1.43:8080/master/static/js/plugins/layer/skin/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/text/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/application/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/URLglobal/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/URLglobal/img/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/URLglobal/css/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/my/static/img/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/my/static/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/static/lib/metronic/scripts/URLglobal/plugins/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/my/static/img/bg/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/css/patterns/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/echarts/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/js/echarts/img/弱点PUT,DELETE等级中危URL http://
10.
10.
1.43:8080/master/static/img/弱点PUT,DELETE等级中危http://
10.
10.
1.43:8080/master/static/js/plugins/layer/skinURL/default/弱点PUT,DELETE等级中危
2.
1.
4.
2.低危漏洞
2.
1.
4.
2.
1.开启方法optionsURL http://
10.
10.
1.43:8080/master/view/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/弱点PUT,DELETE等级低危URL http://
10.
10.
1.43:8080/master/static/js/弱点PUT,DELETE等级低危。
个人认证
优秀文档
获得点赞 0