Details
Alert ID 100007
Alert Type Script Passive
Status alpha
Risk Informational
CWE 311
WASC 13
Technologies Targeted All
Tags CWE-311
More Info Scan Rule Help

Summary

A Base64-encoded string has been found in the HTTP response body. Base64-encoded data may contain sensitive information such as usernames, passwords or cookies which should be further inspected.

Solution

Base64-encoding should not be used to store or send sensitive information.

Other Info

References

Code

passive/find base64 strings.js