Burp Suite User Forum

Create new post

what is the positive or false positive? I hope you answer me please. (Content type incorrectly stated)

LUCAS | Last updated: Nov 03, 2021 09:32PM UTC

Issue detail The response states that the content type is multipart/mixed. However, it actually appears to contain unrecognized content. The following browsers may interpret the response as HTML: Internet Explorer 11 Internet Explorer 11 (Compatibility Mode) Edge This issue was found in multiple locations under the reported path Issue remediation For every response containing a message body, the application should include a single Content-type header that correctly and unambiguously states the MIME type of the content in the response body.Additionally, the response header "X-content-type-options: nosniff" should be returned in all responses to reduce the likelihood that browsers will interpret content in a way that disregards the Content-type header. HTTP/1.1 201 Created Date: Mon, 13 Sep 2021 14:38:34 GMT Server: Apache Strict-Transport-Security: max-age=31536000; includeSubDomains X-Powered-By: Servlet/3.1 X-OneAgent-JS-Injection: true Accept-Ranges: bytes X-Request-Digest: 1nyIlYhDpZQG9t-u60C8mg X-DataSource-Digest: 1nyIlYhDpZQG9t-u60C8mg Cache-Control: public ETag: "1631543914:dtagent10213210506081349rNAc:dtagent10213210506081349rNAc" Last-Modified: Mon, 13 Sep 2021 14:38:32 GMT Content-Length: 68197 Server-Timing: dtRpid;desc="568495304" Content-Type: multipart/mixed; boundary=V2h87MjTx4PMMZrYhKvp2b7RHXcs Content-Language: en-US-WIN Set-Cookie: WSP9-PNEGOCIOS=rd5o00000000000000000000ffff0acd3a61o80; expires=Mon, 13-Sep-2021 23:58:34 GMT; path=/pnegocios2/; Httponly Via: 1.1 wwwn.bradescoseguros.com.br (Access Gateway-ag-77B1B8C198108543-117992592) Connection: close --V2h87MjTx4PMMZrYhKvp2b7RHXcs Content-Type: application/soap+xml Content-Transfer-Encoding: binary X-DataSource-Digest: XeQzIS1xrGfdXjpFRHgkaA Content-Language: en Last-Modified: Thu, 01 J

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.