Forum Discussion
HTML Code injection Not detected by ASM
There was PT conducted on our application and was reported to be HTML injection vulnerable.
URL used for evidence of exploitation is:
ASM have neither triggered 'onerror' attack signatures which are enforced nor did trigger any meta character violations.
Isn't ASM capable of detecting attack in this pattern?
Please suggest.
I can confirm this is blocked by F5. %00 generates a http compliance failed (null in request) violation. Meta characters also generate an illegal metacharacter in value violation. Check your policy settings and enforcement.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com