Possible User ID and Password Sent Within a Web Form (POST)

info Nessus Network Monitor Plugin ID 4672

Synopsis

The remote web client posted a form with what appears to be an embedded user ID and password.

Description

The remote web client posted a form with what appears to be an embedded user ID and password. You should manually verify that confidential data is not being leaked from the network.

Solution

Ensure that confidential data is not passed via plaintext form fields. Note: PVS only reports on the first occurence of this item on a web server. Parse your entire web source for similar occurrences.

Plugin Details

Severity: Info

ID: 4672

Family: Data Leakage

Published: 9/15/2008

Updated: 6/1/2015