Burp Suite User Forum

Create new post

Cross-site scripting : reflected --> justification

Dhandapani, | Last updated: Sep 05, 2021 03:00PM UTC

Hi Team, Need some help to suppress false positives for XSS as below. Is there a way where I can get an justification, because it just shows "File not found" exception in the response. How can we do this ? Request GET /hbt/resourcesmnqbc%3cscript%3ealert(1)%3c/script%3eclkf7/assets/js/****** HTTP/1.1 Host: cnsi-qapdapp01.cns-inc.com:5022 Cookie: JSESSIONID=00006fNCUhDQ04KE2Mu5cZVgMHE:-1 Upgrade-Insecure-Requests: 1 Accept-Encoding: gzip, deflate Accept: */* Accept-Language: en-US,en-GB;q=0.9,en;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36 Connection: close Cache-Control: max-age=0 Response HTTP/1.1 404 Not Found X-Powered-By: Servlet/3.0 Content-Type: text/html; charset=utf-8 $WSEP: Content-Language: en-US Content-Length: 373 Connection: Close Date: Mon, 30 Aug 2021 19:21:35 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <html lang="en"> <head> <meta charset="utf-8" http-equiv="Content-Type" content="text/html ...[SNIP]... <body> Exception: SRVE0190E: File not found: /resourcesmnqbc<script>alert(1)</script> </body>

Hannah, PortSwigger Agent | Last updated: Sep 07, 2021 10:58AM UTC

Thank you for your post. We have responded to your email.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.