web application report

76
Web Application Report This report includes important security information about your web application. OWASP Top 10 2017 Report This report was created by IBM Security AppScan Standard 9.0.3.9, Rules: 13536 Scan started: 7/20/2018 2:32:02 AM

Upload: others

Post on 05-Jan-2022

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Web Application Report

Web Application Report

Thisreportincludesimportantsecurityinformationaboutyourwebapplication.

OWASP Top 10 2017 ReportThisreportwascreatedbyIBMSecurityAppScanStandard9.0.3.9,Rules:13536Scanstarted:7/20/20182:32:02AM

Page 2: Web Application Report

Regulations

OWASP Top Ten 2017 – The Ten Most Critical WebApplication Security Risks

SummaryDescription

ThegoaloftheTop10projectistoraiseawarenessaboutapplicationsecuritybyidentifyingsomeofthemostcriticalrisksfacingorganizations.Developmentprojectsshouldaddressthesepotentialrisksintheirrequirementsdocumentsanddesign,buildandtesttheirapplicationstoensurethattheyhavetakenthenecessarymeasurestoreducetheseriskstotheminimum.Projectmanagersshouldincludetimeandbudgetforapplicationsecurityactivitiesincludingdevelopertraining,applicationsecuritypolicydevelopment,securitymechanismdesignanddevelopment,penetrationtesting,andsecuritycodereviewaspartovertheoverallefforttoaddresstherisks.

TheprimaryaimoftheOWASPTop10istoeducatedevelopers,designers,architects,managers,andorganizationsabouttheconsequencesofthemostimportantwebapplicationsecurityrisks.TheTop10providesbasicguidanceonhowtoaddressagainsttheserisksandwheretogotolearnmoreonhowtoaddressthem.

Althoughsetoutasaneducationpiece,ratherthanastandardoraregulation,itisimportanttonotethatseveralprominentindustryandgovernmentregulatorsarereferencingtheOWASPtopten.ThesebodiesincludeamongothersVISAUSA,MasterCardInternationalandtheAmericanFederalTradeCommission(FTC).

However,accordingtotheOWASPteamtheOWASPtoptenfirstandforemostaneducationpiece,notastandard.TheOWASPteamsuggeststhatanyorganizationabouttoadopttheTopTenpaperasapolicyorstandardtoconsultwiththeOWASPteamfirst.

WhatChangedFrom2013to2017?

ThethreatlandscapeforapplicationsandAPIsconstantlychanges.Keyfactorsinthisevolutionaretherapidadoptionofnewtechnologies(includingcloud,containers,andAPIs),theaccelerationandautomationofsoftwaredevelopmentprocesseslikeAgileandDevOps,theexplosionofthird-partylibrariesandframeworks,andadvancesmadebyattackers.ThesefactorsfrequentlymakeapplicationsandAPIsmoredifficulttoanalyze,andcansignificantlychangethethreatlandscape.Tokeeppace,theOWASPorganizationperiodicallyupdatetheOWASPTop10.Inthis2017release,followingchangesweremade:

Merged2013-A4:"InsecureDirectObjectReferences"and2013-A7:"MissingFunctionLevelAccessControl"into2017-A5:"BrokenAccessControl".

Dropped2013-A8:"Cross-SiteRequestForgery(CSRF)"asmanyframeworksincludeCSRFdefenses,itwasfoundinonly5%ofapplications.

7/24/2018 QA-531 1

Page 3: Web Application Report

Dropped2013-A10:"UnvalidatedRedirectsandForwards",whilefoundinapproximatelyin8%ofapplications,itwasedgedoutoverallbyXXE.

Added2017-A4:"XMLExternalEntities(XXE)".

Added2017-A8:"InsecureDeserialization".

Added2017-A10:"InsufficientLoggingandMonitoring".

CoveredEntities

Allcompaniesandotherentitiesthatdevelopanykindofwebapplicationcodeareencouragedtoaddressthetoptenlistaspartoftheiroverallsecurityriskmanagement.AdoptingtheOWASPTopTenisaneffectivefirststeptowardschangingthesoftwaredevelopmentculturewithintheorganizationintoonethatproducessecurecode.

FormoreinformationonOWASPTopTen,pleasereviewthe-OWASPTopTen2017–TheTenMostCriticalWebApplicationSecurityRisks,athttp://www.owasp.org

Formoreinformationonsecuringwebapplications,pleasevisithttp://www-03.ibm.com/software/products/en/category/application-security

The information provided does not constitute legal advice. The results of a vulnerability assessment will demonstratepotential vulnerabilities in your application that should be corrected in order to reduce the likelihood that yourinformation will be compromised. As legal advice must be tailored to the specific application of each law, and lawsare constantly changing, nothing provided herein should be used as a substitute for the advice of competent counsel.IBM customers are responsible for ensuring their own compliance with legal requirements. It is the customer's soleresponsibility to obtain advice of competent legal counsel as to the identification and interpretation of any relevantlaws and regulatory requirements that may affect the customer's business and any actions the customer may need totake to comply with such laws.

GDPR ArticlesIssuesdetectedacross5/10sectionsoftheregulation:

Sections Number of Issues

A1-Injection 0A2-Brokenauthentication 1A3-SensitiveDataExposure 217A4-XMLExternalEntities(XXE) 0A5-BrokenAccessControl 219A6-SecurityMisconfiguration 218A7-Crosssitescripting(XSS) 0A8-InsecureDeserialization 0A9-UsingComponentswithKnownVulnerabilities 345A10-InsufficientLoggingandMonitoring 0

7/24/2018 QA-531 2

Page 4: Web Application Report

Section Violation By Issue348Uniqueissuesdetectedacross5/10sectionsoftheregulation:

URL Entity Issue Type Sections

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

Missingorinsecure"Content-Security-Policy"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/ Missingorinsecure"X-Content-Type-Options"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/ BodyParametersAcceptedinQuery

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/ Missingorinsecure"X-XSS-Protection"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

Missingorinsecure"Content-Security-Policy"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

Missingorinsecure"X-Content-Type-Options"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

Missingorinsecure"X-Content-Type-Options"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

Missingorinsecure"X-XSS-Protection"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

Missingorinsecure"X-XSS-Protection"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/ OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/order order Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js Missingorinsecure"Content-Security-Policy"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js Missingorinsecure"X-Content-Type-Options"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js Missingorinsecure"X-XSS-Protection"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/ Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/ Missingorinsecure"Content-Security-Policy"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/search/gss/1234

1234 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/699 699 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de de OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

7/24/2018 QA-531 3

Page 5: Web Application Report

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js drupal.js Missingorinsecure"Content-Security-Policy"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js drupal.js Missingorinsecure"X-Content-Type-Options"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js drupal.js Missingorinsecure"X-XSS-Protection"header

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/themes/bootstrap/js/bootstrap.min.js

bootstrap.min.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr fr Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/order order OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/homepage homepage Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/lube lube Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/products products OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr fr OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/air air Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de de Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/homepage homepage OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/products products Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/lube lube OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fuel fuel OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/air air OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fuel fuel Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fleetmanager fleetmanager Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fluidanalysis fluidanalysis OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/hydraulics hydraulics Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/hydraulics hydraulics OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fluidanalysis fluidanalysis Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fleetmanager fleetmanager OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/product-releases

product-releases

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

7/24/2018 QA-531 4

Page 6: Web Application Report

http://cumminsfiltration-stg.bitnamiapp.com/literature/additives

additives Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature literature Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/transmission transmission Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/transmission transmission OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/product-releases

product-releases

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/fluid-analysis

fluid-analysis OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/air air OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/hydraulic

hydraulic Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature literature OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/cooling

cooling Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/applications

applications Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/cooling

cooling OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/additives

additives OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/applications

applications OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/air air Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/fuel fuel Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/hydraulic

hydraulic OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/crankcase-ventilation

crankcase-ventilation

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/msds msds Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/fuel fuel OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/crankcase-ventilation

crankcase-ventilation

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/lube lube Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/fluid-analysis

fluid-analysis Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/lube lube OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/oil-and-gas

oil-and-gas Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/msds msds OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

7/24/2018 QA-531 5

Page 7: Web Application Report

http://cumminsfiltration-stg.bitnamiapp.com/customerassistance

customerassistance

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fleetguardaccess

fleetguardaccess

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/literature/oil-and-gas

oil-and-gas OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/training training Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/warranty warranty Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/training training OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/customerassistance

customerassistance

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator retail-locator EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fleetguardaccess

fleetguardaccess

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/faq faq Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/792 792 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/completesolution

completesolution

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/warranty warranty OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/faq faq OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator retail-locator Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator retail-locator OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/contactus contactus Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/cookies cookies OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/completesolution

completesolution

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/terms-and-conditions

terms-and-conditions

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/sitemap sitemap Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/contactus contactus OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/terms-and-conditions

terms-and-conditions

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/cookies cookies Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/sitemap sitemap OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/search/gss/1234

1234 Unsafethird-partylink(target="_blank")

A9

7/24/2018 QA-531 6

Page 8: Web Application Report

http://cumminsfiltration-stg.bitnamiapp.com/delivery delivery OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/FBUDemo/ Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/es/order order Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/addthis/addthis.js

addthis.js OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/es/order order OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/products products Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/delivery delivery Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326 1326 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/products products OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/792 792 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/792 792 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2082 2082 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/it/node/792 792 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/it/node/792 792 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2016 2016 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326 1326 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/views_bootstrap/js/views-bootstrap-carousel.js

views-bootstrap-carousel.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/sitemap sitemap OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/699 699 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2736 2736 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2016 2016 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/688 688 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/699 699 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/688 688 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/homepage homepage Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/Cookies Cookies Unsafethird-partylink A9

7/24/2018 QA-531 7

Page 9: Web Application Report

(target="_blank")http://cumminsfiltration-stg.bitnamiapp.com/fr/air air OverlyPermissiveCORS

AccessPolicyA3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/homepage homepage OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/lube lube Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2736 2736 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/Cookies Cookies OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/sitemap sitemap Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/air air Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/lube lube OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/crankcaseventilation

crankcaseventilation

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetmanager fleetmanager OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/hydraulics hydraulics Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/transmission transmission OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/crankcaseventilation

crankcaseventilation

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/product-releases

product-releases

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/hydraulics hydraulics OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/fluidanalysis fluidanalysis Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/product-releases

product-releases

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/699 699 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetmanager fleetmanager Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/msds msds Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature literature OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/fluidanalysis fluidanalysis OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/transmission transmission Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature literature Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/contactus contactus Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetguardacc fleetguardacc OverlyPermissiveCORS A3,A5,

7/24/2018 QA-531 8

Page 10: Web Application Report

ess ess AccessPolicy A6,A9http://cumminsfiltration-stg.bitnamiapp.com/fr/training training Unsafethird-partylink

(target="_blank")A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/mediacenter mediacenter OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/training training OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/customerassistance

customerassistance

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/msds msds OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/customerassistance

customerassistance

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/mediacenter mediacenter Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/2736 2736 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/sitemap sitemap OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/history history OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetguardaccess

fleetguardaccess

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/infiniteCarousel.js

infiniteCarousel.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/contactus contactus OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/2736 2736 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/history history Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/Cookies Cookies Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1016 1016 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/node/2986 2986 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/optiair optiair Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/Cookies Cookies OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/sitemap sitemap Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/node/2986 2986 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/galleryformatter.js

galleryformatter.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/videos videos Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/eUpdate eUpdate Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/videos videos OverlyPermissiveCORS A3,A5,

7/24/2018 QA-531 9

Page 11: Web Application Report

AccessPolicy A6,A9http://cumminsfiltration-stg.bitnamiapp.com/de/node/1016 1016 Unsafethird-partylink

(target="_blank")A9

http://cumminsfiltration-stg.bitnamiapp.com/nanoforce nanoforce Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/optiair optiair OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/it/node/1019 1019 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/eUpdate eUpdate OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/directflow directflow OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/nanoforce nanoforce OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/directflow directflow Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/magnumrs magnumrs Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/it/node/1019 1019 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/magnumrs magnumrs OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2082 2082 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilterlube spinonfilterlube

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/centrifuge centrifuge Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilters spinonfilters Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilters spinonfilters OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilterlube spinonfilterlube

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/centrifuge centrifuge OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/es/fluidanalysis fluidanalysis Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1272 1272 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1272 1272 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2082 2082 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sensors sensors Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/sensors sensors OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2082 2082 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/es/fluidanalysis fluidanalysis OverlyPermissiveCORS A3,A5,

7/24/2018 QA-531 10

Page 12: Web Application Report

AccessPolicy A6,A9http://cumminsfiltration-stg.bitnamiapp.com/print/1272 1272 EmailAddressPattern

FoundA3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1272 1272 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2077 2077 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2077 2077 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2082 2082 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1272 1272 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2077 2077 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2077 2077 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/additives

additives Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/additives

additives OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1060 1060 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2077 2077 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/699 699 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/699 699 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1060 1060 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1276 1276 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1060 1060 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2085 2085 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/es/literature/fuel

fuel Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/692 692 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/crankcase-ventilation

crankcase-ventilation

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/es/literature/fuel

fuel OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/crankcase-ventilation

crankcase-ventilation

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1172 1172 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform_conditional/webform_conditional.js

webform_conditional.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1182 1182 OverlyPermissiveCORS A3,A5,

7/24/2018 QA-531 11

Page 13: Web Application Report

AccessPolicy A6,A9http://cumminsfiltration-stg.bitnamiapp.com/de/node/692 692 Unsafethird-partylink

(target="_blank")A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1276 1276 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/692 692 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2085 2085 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/692 692 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/692 692 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/692 692 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/es/warranty warranty Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform/js/webform.js

webform.js OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/misc/form.js form.js OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/misc/textarea.js textarea.js OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/eloqua/eloqua_webform/eloqua_webform.js

eloqua_webform.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/captcha/captcha.js

captcha.js OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1276 1276 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/es/warranty warranty OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/def def Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/697 697 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1276 1276 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/697 697 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1276 1276 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/688 688 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1276 1276 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/688 688 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/analysis analysis OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/closedcvfilters closedcvfilters

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/688 688 OverlyPermissiveCORS A3,A5,

7/24/2018 QA-531 12

Page 14: Web Application Report

AccessPolicy A6,A9http://cumminsfiltration-stg.bitnamiapp.com/conventional conventional Unsafethird-partylink

(target="_blank")A9

http://cumminsfiltration-stg.bitnamiapp.com/search/gss/cummins

cummins Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/seapro seapro OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/aluminumcorrosion

aluminumcorrosion

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/conventional conventional OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326 1326 BodyParametersAcceptedinQuery

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/def def OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/analysis analysis Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/aluminumcorrosion

aluminumcorrosion

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/closedcvfilters closedcvfilters

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/search search Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/699 699 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss/1234

1234 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/dieselpro dieselpro Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/search/gss gss Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/dieselpro dieselpro OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/seapro seapro Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/closedcvfilters

closedcvfilters

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss gss Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/ OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/node/ Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss gss BodyParametersAcceptedinQuery

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/it/printpdf/792 792 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/search/gss/1234

1234 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/hybrid hybrid Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/conventional conventional Unsafethird-partylink A9

7/24/2018 QA-531 13

Page 15: Web Application Report

(target="_blank")http://cumminsfiltration-stg.bitnamiapp.com/print/ OverlyPermissiveCORS

AccessPolicyA3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/closedcvfilters

closedcvfilters

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/literature literature TemporaryFileDownload A5,A6http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771 1771 EmailAddressPattern

FoundA3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771 1771 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/printpdf/1771 1771 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/hybrid hybrid OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/692 692 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/conventional conventional OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2082

2082 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/coolantfiltration

coolantfiltration

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1163 1163 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/es/directflow directflow OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/coolantfiltration

coolantfiltration

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/es/directflow directflow Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1163 1163 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1272

1272 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/ EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1163 1163 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1276

1276 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/es/qualitycert qualitycert OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2077

2077 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1163 1163 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/773 773 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/es/qualitycert qualitycert Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/es/hybrid hybrid OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

7/24/2018 QA-531 14

Page 16: Web Application Report

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1166 1166 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1273 1273 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2725 2725 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/1273 1273 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/773 773 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/773 773 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2725 2725 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/774 774 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2724 2724 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2725 2725 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/2724 2724 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2724 2724 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1273 1273 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/es/hybrid hybrid Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/774 774 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/976 976 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/774 774 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/774 774 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/772 772 Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/print/772 772 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/772 772 OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/976 976 EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature literature TemporaryFileDownload A5,A6http://cumminsfiltration-stg.bitnamiapp.com/print/976 976 OverlyPermissiveCORS

AccessPolicyA3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login login Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/node node Unsafethird-partylink A9

7/24/2018 QA-531 15

Page 17: Web Application Report

(target="_blank")http://cumminsfiltration-stg.bitnamiapp.com/node node OverlyPermissiveCORS

AccessPolicyA3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/search/site/cummins

cummins Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/rss.xml rss.xml OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login login OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/de/regions/cis cis Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/node node Unsafethird-partylink(target="_blank")

A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/node node OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/regions/cis cis OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/js/encryption_submissions.js

encryption_submissions.js

OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/fr/rss.xml rss.xml OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/rss.xml rss.xml OverlyPermissiveCORSAccessPolicy

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

EmailAddressPatternFound

A3,A5,A6,A9

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login pass UnencryptedLoginRequest

A2,A3,A5

Detailed Security Issues by Sections

A1-Injection 0

H A2-Brokenauthentication 1

7/24/2018 QA-531 16

Page 18: Web Application Report

High

High

Unencrypted Login RequestRisk: Itmaybepossibletostealuserlogininformationsuchasusernamesandpasswordsthataresent

unencrypted

Causes: Sensitiveinputfieldssuchasusernames,passwordandcreditcardnumbersarepassedunencrypted

Fix: AlwaysuseSSLandPOST(body)parameterswhensendingsensitiveinformation.

CVSS Score: 8.5

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

pass

H A3-SensitiveDataExposure 217

Unencrypted Login RequestRisk: Itmaybepossibletostealuserlogininformationsuchasusernamesandpasswordsthataresent

unencrypted

Causes: Sensitiveinputfieldssuchasusernames,passwordandcreditcardnumbersarepassedunencrypted

Fix: AlwaysuseSSLandPOST(body)parameterswhensendingsensitiveinformation.

CVSS Score: 8.5

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

pass

7/24/2018 QA-531 17

Page 19: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Body Parameters Accepted in QueryRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Donotacceptbodyparametersthataresentinthequerystring

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss

gss

Missing or insecure "Content-Security-Policy" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"Content-Security-Policy"headerwithsecurepolicies

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 18

Page 20: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Missing or insecure "X-Content-Type-Options" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-Content-Type-Options"headerwith"nosniff"value

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

Missing or insecure "X-XSS-Protection" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-XSS-Protection"headerwithvalue'1'(enabled)

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 19

Page 21: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Overly Permissive CORS Access PolicyRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Modifythe"Access-Control-Allow-Origin"headertocontainonlyallowedsites

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de

de

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/themes/bootstrap/js/bootstrap.min.js

bootstrap.min.js

http://cumminsfiltration-stg.bitnamiapp.com/order

order

http://cumminsfiltration-stg.bitnamiapp.com/products

products

http://cumminsfiltration-stg.bitnamiapp.com/fr

fr

http://cumminsfiltration-stg.bitnamiapp.com/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/hydraulics

hydraulics

http://cumminsfiltration-stg.bitnamiapp.com/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/transmission

transmission

7/24/2018 QA-531 20

Page 22: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/literature/fluid-analysis

fluid-analysis

http://cumminsfiltration-stg.bitnamiapp.com/literature/air

air

http://cumminsfiltration-stg.bitnamiapp.com/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/literature/cooling

cooling

http://cumminsfiltration-stg.bitnamiapp.com/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/literature/applications

applications

http://cumminsfiltration-stg.bitnamiapp.com/literature/hydraulic

hydraulic

http://cumminsfiltration-stg.bitnamiapp.com/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/literature/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/literature/oil-and-gas

oil-and-gas

http://cumminsfiltration-stg.bitnamiapp.com/training

training

http://cumminsfiltration-stg.bitnamiapp.com/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/faq

faq

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/cookies

cookies

http://cumminsfiltration-stg.bitnamiapp.com/completesolution

completesolution

http://cumminsfiltration-stg.bitnamiapp.com/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/terms-and-conditions

terms-and-conditions

7/24/2018 QA-531 21

Page 23: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/delivery

delivery

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/addthis/addthis.js

addthis.js

http://cumminsfiltration-stg.bitnamiapp.com/es/order

order

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/fr/products

products

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/it/node/792

792

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/views_bootstrap/js/views-bootstrap-carousel.js

views-bootstrap-carousel.js

http://cumminsfiltration-stg.bitnamiapp.com/de/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/de/node/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2016

2016

http://cumminsfiltration-stg.bitnamiapp.com/de/node/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fr/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/fr/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fr/crankcaseventilation

crankcaseventilation

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/fr/transmission

transmission

http://cumminsfiltration-stg.bitnamiapp.com/fr/hydraulics

hydraulics

7/24/2018 QA-531 22

Page 24: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/fr/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/fr/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/fr/mediacenter

mediacenter

http://cumminsfiltration-stg.bitnamiapp.com/fr/training

training

http://cumminsfiltration-stg.bitnamiapp.com/fr/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fr/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/fr/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/fr/history

history

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/infiniteCarousel.js

infiniteCarousel.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1016

1016

http://cumminsfiltration-stg.bitnamiapp.com/fr/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/node/2986

2986

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/galleryformatter.js

galleryformatter.js

http://cumminsfiltration-stg.bitnamiapp.com/videos

videos

http://cumminsfiltration-stg.bitnamiapp.com/optiair

optiair

http://cumminsfiltration-stg.bitnamiapp.com/eUpdate

eUpdate

http://cumminsfiltration-stg.bitnamiapp.com/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/nanoforce

nanoforce

7/24/2018 QA-531 23

Page 25: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/it/node/1019

1019

http://cumminsfiltration-stg.bitnamiapp.com/magnumrs

magnumrs

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilterlube

spinonfilterlube

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilters

spinonfilters

http://cumminsfiltration-stg.bitnamiapp.com/centrifuge

centrifuge

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/sensors

sensors

http://cumminsfiltration-stg.bitnamiapp.com/es/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/es/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1172

1172

7/24/2018 QA-531 24

Page 26: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform_conditional/webform_conditional.js

webform_conditional.js

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1182

1182

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2085

2085

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/692

692

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform/js/webform.js

webform.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/form.js

form.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/textarea.js

textarea.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/eloqua/eloqua_webform/eloqua_webform.js

eloqua_webform.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/captcha/captcha.js

captcha.js

http://cumminsfiltration-stg.bitnamiapp.com/es/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/de/node/697

697

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/analysis

analysis

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/688

688

http://cumminsfiltration-stg.bitnamiapp.com/seapro

seapro

http://cumminsfiltration-stg.bitnamiapp.com/aluminumcorrosion

aluminumcorrosion

http://cumminsfiltration-stg.bitnamiapp.com/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/def

def

7/24/2018 QA-531 25

Page 27: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/dieselpro

dieselpro

http://cumminsfiltration-stg.bitnamiapp.com/fr/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/node/

http://cumminsfiltration-stg.bitnamiapp.com/it/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/printpdf/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/fr/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/es/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/fr/coolantfiltration

coolantfiltration

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/es/qualitycert

qualitycert

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/es/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1166

1166

7/24/2018 QA-531 26

Page 28: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/976

976

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/rss.xml

rss.xml

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

login

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/regions/cis

cis

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/js/encryption_submissions.js

encryption_submissions.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/rss.xml

rss.xml

7/24/2018 QA-531 27

Page 29: Web Application Report

Low http://cumminsfiltration-stg.bitnamiapp.com/rss.xml

rss.xml

7/24/2018 QA-531 28

Page 30: Web Application Report

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Email Address Pattern FoundRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocations

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Removee-mailaddressesfromthewebsite

CVSS Score: 0.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

7/24/2018 QA-531 29

Page 31: Web Application Report

Informational

Informational

Informational

Informational

High

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

A4-XMLExternalEntities(XXE) 0

H A5-BrokenAccessControl 219

Unencrypted Login RequestRisk: Itmaybepossibletostealuserlogininformationsuchasusernamesandpasswordsthataresent

unencrypted

Causes: Sensitiveinputfieldssuchasusernames,passwordandcreditcardnumbersarepassedunencrypted

Fix: AlwaysuseSSLandPOST(body)parameterswhensendingsensitiveinformation.

CVSS Score: 8.5

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

pass

7/24/2018 QA-531 30

Page 32: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Body Parameters Accepted in QueryRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Donotacceptbodyparametersthataresentinthequerystring

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss

gss

Missing or insecure "Content-Security-Policy" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"Content-Security-Policy"headerwithsecurepolicies

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 31

Page 33: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Missing or insecure "X-Content-Type-Options" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-Content-Type-Options"headerwith"nosniff"value

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

Missing or insecure "X-XSS-Protection" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-XSS-Protection"headerwithvalue'1'(enabled)

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 32

Page 34: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Overly Permissive CORS Access PolicyRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Modifythe"Access-Control-Allow-Origin"headertocontainonlyallowedsites

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de

de

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/themes/bootstrap/js/bootstrap.min.js

bootstrap.min.js

http://cumminsfiltration-stg.bitnamiapp.com/order

order

http://cumminsfiltration-stg.bitnamiapp.com/products

products

http://cumminsfiltration-stg.bitnamiapp.com/fr

fr

http://cumminsfiltration-stg.bitnamiapp.com/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/hydraulics

hydraulics

http://cumminsfiltration-stg.bitnamiapp.com/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/transmission

transmission

7/24/2018 QA-531 33

Page 35: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/literature/fluid-analysis

fluid-analysis

http://cumminsfiltration-stg.bitnamiapp.com/literature/air

air

http://cumminsfiltration-stg.bitnamiapp.com/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/literature/cooling

cooling

http://cumminsfiltration-stg.bitnamiapp.com/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/literature/applications

applications

http://cumminsfiltration-stg.bitnamiapp.com/literature/hydraulic

hydraulic

http://cumminsfiltration-stg.bitnamiapp.com/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/literature/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/literature/oil-and-gas

oil-and-gas

http://cumminsfiltration-stg.bitnamiapp.com/training

training

http://cumminsfiltration-stg.bitnamiapp.com/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/faq

faq

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/cookies

cookies

http://cumminsfiltration-stg.bitnamiapp.com/completesolution

completesolution

http://cumminsfiltration-stg.bitnamiapp.com/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/terms-and-conditions

terms-and-conditions

7/24/2018 QA-531 34

Page 36: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/delivery

delivery

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/addthis/addthis.js

addthis.js

http://cumminsfiltration-stg.bitnamiapp.com/es/order

order

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/fr/products

products

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/it/node/792

792

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/views_bootstrap/js/views-bootstrap-carousel.js

views-bootstrap-carousel.js

http://cumminsfiltration-stg.bitnamiapp.com/de/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/de/node/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2016

2016

http://cumminsfiltration-stg.bitnamiapp.com/de/node/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fr/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/fr/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fr/crankcaseventilation

crankcaseventilation

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/fr/transmission

transmission

http://cumminsfiltration-stg.bitnamiapp.com/fr/hydraulics

hydraulics

7/24/2018 QA-531 35

Page 37: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/fr/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/fr/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/fr/mediacenter

mediacenter

http://cumminsfiltration-stg.bitnamiapp.com/fr/training

training

http://cumminsfiltration-stg.bitnamiapp.com/fr/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fr/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/fr/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/fr/history

history

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/infiniteCarousel.js

infiniteCarousel.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1016

1016

http://cumminsfiltration-stg.bitnamiapp.com/fr/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/node/2986

2986

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/galleryformatter.js

galleryformatter.js

http://cumminsfiltration-stg.bitnamiapp.com/videos

videos

http://cumminsfiltration-stg.bitnamiapp.com/optiair

optiair

http://cumminsfiltration-stg.bitnamiapp.com/eUpdate

eUpdate

http://cumminsfiltration-stg.bitnamiapp.com/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/nanoforce

nanoforce

7/24/2018 QA-531 36

Page 38: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/it/node/1019

1019

http://cumminsfiltration-stg.bitnamiapp.com/magnumrs

magnumrs

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilterlube

spinonfilterlube

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilters

spinonfilters

http://cumminsfiltration-stg.bitnamiapp.com/centrifuge

centrifuge

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/sensors

sensors

http://cumminsfiltration-stg.bitnamiapp.com/es/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/es/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1172

1172

7/24/2018 QA-531 37

Page 39: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform_conditional/webform_conditional.js

webform_conditional.js

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1182

1182

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2085

2085

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/692

692

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform/js/webform.js

webform.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/form.js

form.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/textarea.js

textarea.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/eloqua/eloqua_webform/eloqua_webform.js

eloqua_webform.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/captcha/captcha.js

captcha.js

http://cumminsfiltration-stg.bitnamiapp.com/es/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/de/node/697

697

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/analysis

analysis

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/688

688

http://cumminsfiltration-stg.bitnamiapp.com/seapro

seapro

http://cumminsfiltration-stg.bitnamiapp.com/aluminumcorrosion

aluminumcorrosion

http://cumminsfiltration-stg.bitnamiapp.com/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/def

def

7/24/2018 QA-531 38

Page 40: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/dieselpro

dieselpro

http://cumminsfiltration-stg.bitnamiapp.com/fr/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/node/

http://cumminsfiltration-stg.bitnamiapp.com/it/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/printpdf/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/fr/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/es/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/fr/coolantfiltration

coolantfiltration

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/es/qualitycert

qualitycert

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/es/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1166

1166

7/24/2018 QA-531 39

Page 41: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/976

976

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/rss.xml

rss.xml

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

login

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/regions/cis

cis

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/js/encryption_submissions.js

encryption_submissions.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/rss.xml

rss.xml

7/24/2018 QA-531 40

Page 42: Web Application Report

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/rss.xml

rss.xml

Temporary File DownloadRisk: Itispossibletodownloadtemporaryscriptfiles,whichcanexposetheapplicationlogicandother

sensitiveinformationsuchasusernamesandpasswords

Causes: Temporaryfileswereleftinproductionenvironment

Fix: Removeoldversionsoffilesfromthevirtualdirectory

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature

literature

7/24/2018 QA-531 41

Page 43: Web Application Report

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Email Address Pattern FoundRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocations

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Removee-mailaddressesfromthewebsite

CVSS Score: 0.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

7/24/2018 QA-531 42

Page 44: Web Application Report

Informational

Informational

Informational

Informational

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

L A6-SecurityMisconfiguration 218

Body Parameters Accepted in QueryRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Donotacceptbodyparametersthataresentinthequerystring

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss

gss

7/24/2018 QA-531 43

Page 45: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Missing or insecure "Content-Security-Policy" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"Content-Security-Policy"headerwithsecurepolicies

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

Missing or insecure "X-Content-Type-Options" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-Content-Type-Options"headerwith"nosniff"value

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 44

Page 46: Web Application Report

Low

Low

Low

Low

Low

Missing or insecure "X-XSS-Protection" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-XSS-Protection"headerwithvalue'1'(enabled)

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 45

Page 47: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Overly Permissive CORS Access PolicyRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Modifythe"Access-Control-Allow-Origin"headertocontainonlyallowedsites

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de

de

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/themes/bootstrap/js/bootstrap.min.js

bootstrap.min.js

http://cumminsfiltration-stg.bitnamiapp.com/order

order

http://cumminsfiltration-stg.bitnamiapp.com/products

products

http://cumminsfiltration-stg.bitnamiapp.com/fr

fr

http://cumminsfiltration-stg.bitnamiapp.com/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/hydraulics

hydraulics

http://cumminsfiltration-stg.bitnamiapp.com/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/transmission

transmission

7/24/2018 QA-531 46

Page 48: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/literature/fluid-analysis

fluid-analysis

http://cumminsfiltration-stg.bitnamiapp.com/literature/air

air

http://cumminsfiltration-stg.bitnamiapp.com/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/literature/cooling

cooling

http://cumminsfiltration-stg.bitnamiapp.com/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/literature/applications

applications

http://cumminsfiltration-stg.bitnamiapp.com/literature/hydraulic

hydraulic

http://cumminsfiltration-stg.bitnamiapp.com/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/literature/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/literature/oil-and-gas

oil-and-gas

http://cumminsfiltration-stg.bitnamiapp.com/training

training

http://cumminsfiltration-stg.bitnamiapp.com/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/faq

faq

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/cookies

cookies

http://cumminsfiltration-stg.bitnamiapp.com/completesolution

completesolution

http://cumminsfiltration-stg.bitnamiapp.com/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/terms-and-conditions

terms-and-conditions

7/24/2018 QA-531 47

Page 49: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/delivery

delivery

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/addthis/addthis.js

addthis.js

http://cumminsfiltration-stg.bitnamiapp.com/es/order

order

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/fr/products

products

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/it/node/792

792

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/views_bootstrap/js/views-bootstrap-carousel.js

views-bootstrap-carousel.js

http://cumminsfiltration-stg.bitnamiapp.com/de/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/de/node/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2016

2016

http://cumminsfiltration-stg.bitnamiapp.com/de/node/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fr/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/fr/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fr/crankcaseventilation

crankcaseventilation

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/fr/transmission

transmission

http://cumminsfiltration-stg.bitnamiapp.com/fr/hydraulics

hydraulics

7/24/2018 QA-531 48

Page 50: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/fr/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/fr/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/fr/mediacenter

mediacenter

http://cumminsfiltration-stg.bitnamiapp.com/fr/training

training

http://cumminsfiltration-stg.bitnamiapp.com/fr/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fr/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/fr/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/fr/history

history

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/infiniteCarousel.js

infiniteCarousel.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1016

1016

http://cumminsfiltration-stg.bitnamiapp.com/fr/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/node/2986

2986

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/galleryformatter.js

galleryformatter.js

http://cumminsfiltration-stg.bitnamiapp.com/videos

videos

http://cumminsfiltration-stg.bitnamiapp.com/optiair

optiair

http://cumminsfiltration-stg.bitnamiapp.com/eUpdate

eUpdate

http://cumminsfiltration-stg.bitnamiapp.com/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/nanoforce

nanoforce

7/24/2018 QA-531 49

Page 51: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/it/node/1019

1019

http://cumminsfiltration-stg.bitnamiapp.com/magnumrs

magnumrs

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilterlube

spinonfilterlube

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilters

spinonfilters

http://cumminsfiltration-stg.bitnamiapp.com/centrifuge

centrifuge

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/sensors

sensors

http://cumminsfiltration-stg.bitnamiapp.com/es/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/es/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1172

1172

7/24/2018 QA-531 50

Page 52: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform_conditional/webform_conditional.js

webform_conditional.js

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1182

1182

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2085

2085

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/692

692

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform/js/webform.js

webform.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/form.js

form.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/textarea.js

textarea.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/eloqua/eloqua_webform/eloqua_webform.js

eloqua_webform.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/captcha/captcha.js

captcha.js

http://cumminsfiltration-stg.bitnamiapp.com/es/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/de/node/697

697

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/analysis

analysis

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/688

688

http://cumminsfiltration-stg.bitnamiapp.com/seapro

seapro

http://cumminsfiltration-stg.bitnamiapp.com/aluminumcorrosion

aluminumcorrosion

http://cumminsfiltration-stg.bitnamiapp.com/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/def

def

7/24/2018 QA-531 51

Page 53: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/dieselpro

dieselpro

http://cumminsfiltration-stg.bitnamiapp.com/fr/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/node/

http://cumminsfiltration-stg.bitnamiapp.com/it/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/printpdf/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/fr/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/es/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/fr/coolantfiltration

coolantfiltration

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/es/qualitycert

qualitycert

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/es/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1166

1166

7/24/2018 QA-531 52

Page 54: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/976

976

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/rss.xml

rss.xml

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

login

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/regions/cis

cis

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/js/encryption_submissions.js

encryption_submissions.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/rss.xml

rss.xml

7/24/2018 QA-531 53

Page 55: Web Application Report

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/rss.xml

rss.xml

Temporary File DownloadRisk: Itispossibletodownloadtemporaryscriptfiles,whichcanexposetheapplicationlogicandother

sensitiveinformationsuchasusernamesandpasswords

Causes: Temporaryfileswereleftinproductionenvironment

Fix: Removeoldversionsoffilesfromthevirtualdirectory

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature

literature

7/24/2018 QA-531 54

Page 56: Web Application Report

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Email Address Pattern FoundRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocations

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Removee-mailaddressesfromthewebsite

CVSS Score: 0.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

7/24/2018 QA-531 55

Page 57: Web Application Report

Informational

Informational

Informational

Informational

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

A7-Crosssitescripting(XSS) 0

A8-InsecureDeserialization 0

L A9-UsingComponentswithKnownVulnerabilities 345

Body Parameters Accepted in QueryRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Donotacceptbodyparametersthataresentinthequerystring

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss

gss

7/24/2018 QA-531 56

Page 58: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Missing or insecure "Content-Security-Policy" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"Content-Security-Policy"headerwithsecurepolicies

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

Missing or insecure "X-Content-Type-Options" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-Content-Type-Options"headerwith"nosniff"value

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 57

Page 59: Web Application Report

Low

Low

Low

Low

Low

Missing or insecure "X-XSS-Protection" headerRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Configyourservertousethe"X-XSS-Protection"headerwithvalue'1'(enabled)

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/ui/ui/minified/jquery.ui.core.min.js

jquery.ui.core.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/jquery_update/replace/jquery/1.8/jquery.min.js

jquery.min.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/drupal.js

drupal.js

7/24/2018 QA-531 58

Page 60: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Overly Permissive CORS Access PolicyRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocationsItispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,creditcardnumber,socialsecuritynumberetc.

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Modifythe"Access-Control-Allow-Origin"headertocontainonlyallowedsites

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/misc/jquery.once.js

jquery.once.js

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de

de

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/themes/bootstrap/js/bootstrap.min.js

bootstrap.min.js

http://cumminsfiltration-stg.bitnamiapp.com/order

order

http://cumminsfiltration-stg.bitnamiapp.com/products

products

http://cumminsfiltration-stg.bitnamiapp.com/fr

fr

http://cumminsfiltration-stg.bitnamiapp.com/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/hydraulics

hydraulics

http://cumminsfiltration-stg.bitnamiapp.com/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/transmission

transmission

7/24/2018 QA-531 59

Page 61: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/literature/fluid-analysis

fluid-analysis

http://cumminsfiltration-stg.bitnamiapp.com/literature/air

air

http://cumminsfiltration-stg.bitnamiapp.com/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/literature/cooling

cooling

http://cumminsfiltration-stg.bitnamiapp.com/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/literature/applications

applications

http://cumminsfiltration-stg.bitnamiapp.com/literature/hydraulic

hydraulic

http://cumminsfiltration-stg.bitnamiapp.com/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/literature/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/literature/oil-and-gas

oil-and-gas

http://cumminsfiltration-stg.bitnamiapp.com/training

training

http://cumminsfiltration-stg.bitnamiapp.com/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/faq

faq

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/cookies

cookies

http://cumminsfiltration-stg.bitnamiapp.com/completesolution

completesolution

http://cumminsfiltration-stg.bitnamiapp.com/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/terms-and-conditions

terms-and-conditions

7/24/2018 QA-531 60

Page 62: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/delivery

delivery

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/addthis/addthis.js

addthis.js

http://cumminsfiltration-stg.bitnamiapp.com/es/order

order

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/fr/products

products

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/it/node/792

792

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/views_bootstrap/js/views-bootstrap-carousel.js

views-bootstrap-carousel.js

http://cumminsfiltration-stg.bitnamiapp.com/de/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/de/node/699

699

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2016

2016

http://cumminsfiltration-stg.bitnamiapp.com/de/node/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fr/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/fr/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/fr/crankcaseventilation

crankcaseventilation

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/fr/transmission

transmission

http://cumminsfiltration-stg.bitnamiapp.com/fr/hydraulics

hydraulics

7/24/2018 QA-531 61

Page 63: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/fr/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/fr/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/fr/mediacenter

mediacenter

http://cumminsfiltration-stg.bitnamiapp.com/fr/training

training

http://cumminsfiltration-stg.bitnamiapp.com/fr/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fr/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/fr/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/fr/history

history

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/infiniteCarousel.js

infiniteCarousel.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1016

1016

http://cumminsfiltration-stg.bitnamiapp.com/fr/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/node/2986

2986

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/galleryformatter/theme/galleryformatter.js

galleryformatter.js

http://cumminsfiltration-stg.bitnamiapp.com/videos

videos

http://cumminsfiltration-stg.bitnamiapp.com/optiair

optiair

http://cumminsfiltration-stg.bitnamiapp.com/eUpdate

eUpdate

http://cumminsfiltration-stg.bitnamiapp.com/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/nanoforce

nanoforce

7/24/2018 QA-531 62

Page 64: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/it/node/1019

1019

http://cumminsfiltration-stg.bitnamiapp.com/magnumrs

magnumrs

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilterlube

spinonfilterlube

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilters

spinonfilters

http://cumminsfiltration-stg.bitnamiapp.com/centrifuge

centrifuge

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/sensors

sensors

http://cumminsfiltration-stg.bitnamiapp.com/es/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/es/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1172

1172

7/24/2018 QA-531 63

Page 65: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform_conditional/webform_conditional.js

webform_conditional.js

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1182

1182

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2085

2085

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/de/node/692

692

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/webform/js/webform.js

webform.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/form.js

form.js

http://cumminsfiltration-stg.bitnamiapp.com/misc/textarea.js

textarea.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/eloqua/eloqua_webform/eloqua_webform.js

eloqua_webform.js

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/captcha/captcha.js

captcha.js

http://cumminsfiltration-stg.bitnamiapp.com/es/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/de/node/697

697

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/analysis

analysis

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/688

688

http://cumminsfiltration-stg.bitnamiapp.com/seapro

seapro

http://cumminsfiltration-stg.bitnamiapp.com/aluminumcorrosion

aluminumcorrosion

http://cumminsfiltration-stg.bitnamiapp.com/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/def

def

7/24/2018 QA-531 64

Page 66: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/699

699

http://cumminsfiltration-stg.bitnamiapp.com/dieselpro

dieselpro

http://cumminsfiltration-stg.bitnamiapp.com/fr/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/de/node/

http://cumminsfiltration-stg.bitnamiapp.com/it/printpdf/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/printpdf/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/fr/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/692

692

http://cumminsfiltration-stg.bitnamiapp.com/fr/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/es/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/fr/coolantfiltration

coolantfiltration

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/es/qualitycert

qualitycert

http://cumminsfiltration-stg.bitnamiapp.com/de/printpdf/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/es/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1166

1166

7/24/2018 QA-531 65

Page 67: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/976

976

http://cumminsfiltration-stg.bitnamiapp.com/printpdf/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/rss.xml

rss.xml

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

login

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/node

node

http://cumminsfiltration-stg.bitnamiapp.com/de/regions/cis

cis

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/js/encryption_submissions.js

encryption_submissions.js

http://cumminsfiltration-stg.bitnamiapp.com/fr/rss.xml

rss.xml

7/24/2018 QA-531 66

Page 68: Web Application Report

Low http://cumminsfiltration-stg.bitnamiapp.com/rss.xml

rss.xml

7/24/2018 QA-531 67

Page 69: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Unsafe third-party link (target="_blank")Risk: Itispossibletopersuadeanaiveusertosupplysensitiveinformationsuchasusername,password,

creditcardnumber,socialsecuritynumberetc.

Causes: Therelattributeinthelinkelementisnotsetto"noopenernoreferrer".

Fix: Addtheattributerel="noopenernoreferrer"toeachlinkelementwithtarget="_blank"

CVSS Score: 5.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/order

order

http://cumminsfiltration-stg.bitnamiapp.com/

http://cumminsfiltration-stg.bitnamiapp.com/search/gss/1234

1234

http://cumminsfiltration-stg.bitnamiapp.com/fr

fr

http://cumminsfiltration-stg.bitnamiapp.com/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/air

air

http://cumminsfiltration-stg.bitnamiapp.com/de

de

http://cumminsfiltration-stg.bitnamiapp.com/products

products

http://cumminsfiltration-stg.bitnamiapp.com/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/hydraulics

hydraulics

http://cumminsfiltration-stg.bitnamiapp.com/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/transmission

transmission

http://cumminsfiltration-stg.bitnamiapp.com/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/literature/hydraulic

hydraulic

http://cumminsfiltration-stg.bitnamiapp.com/literature/cooling

cooling

7/24/2018 QA-531 68

Page 70: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/literature/applications

applications

http://cumminsfiltration-stg.bitnamiapp.com/literature/air

air

http://cumminsfiltration-stg.bitnamiapp.com/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/literature/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/literature/fluid-analysis

fluid-analysis

http://cumminsfiltration-stg.bitnamiapp.com/literature/oil-and-gas

oil-and-gas

http://cumminsfiltration-stg.bitnamiapp.com/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/training

training

http://cumminsfiltration-stg.bitnamiapp.com/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/faq

faq

http://cumminsfiltration-stg.bitnamiapp.com/completesolution

completesolution

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/terms-and-conditions

terms-and-conditions

http://cumminsfiltration-stg.bitnamiapp.com/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/cookies

cookies

http://cumminsfiltration-stg.bitnamiapp.com/fr/search/gss/1234

1234

http://cumminsfiltration-stg.bitnamiapp.com/FBUDemo/

http://cumminsfiltration-stg.bitnamiapp.com/es/order

order

http://cumminsfiltration-stg.bitnamiapp.com/fr/products

products

7/24/2018 QA-531 69

Page 71: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/delivery

delivery

http://cumminsfiltration-stg.bitnamiapp.com/it/node/792

792

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2016

2016

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1326

1326

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/de/node/688

688

http://cumminsfiltration-stg.bitnamiapp.com/de/node/699

699

http://cumminsfiltration-stg.bitnamiapp.com/fr/homepage

homepage

http://cumminsfiltration-stg.bitnamiapp.com/de/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/fr/lube

lube

http://cumminsfiltration-stg.bitnamiapp.com/de/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/fr/air

air

http://cumminsfiltration-stg.bitnamiapp.com/fr/hydraulics

hydraulics

http://cumminsfiltration-stg.bitnamiapp.com/fr/crankcaseventilation

crankcaseventilation

http://cumminsfiltration-stg.bitnamiapp.com/fr/product-releases

product-releases

http://cumminsfiltration-stg.bitnamiapp.com/fr/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/699

699

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetmanager

fleetmanager

http://cumminsfiltration-stg.bitnamiapp.com/fr/msds

msds

http://cumminsfiltration-stg.bitnamiapp.com/fr/transmission

transmission

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature

literature

http://cumminsfiltration-stg.bitnamiapp.com/fr/contactus

contactus

http://cumminsfiltration-stg.bitnamiapp.com/fr/training

training

7/24/2018 QA-531 70

Page 72: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/fr/customerassistance

customerassistance

http://cumminsfiltration-stg.bitnamiapp.com/fr/mediacenter

mediacenter

http://cumminsfiltration-stg.bitnamiapp.com/fr/node/2736

2736

http://cumminsfiltration-stg.bitnamiapp.com/fr/fleetguardaccess

fleetguardaccess

http://cumminsfiltration-stg.bitnamiapp.com/fr/history

history

http://cumminsfiltration-stg.bitnamiapp.com/fr/Cookies

Cookies

http://cumminsfiltration-stg.bitnamiapp.com/node/2986

2986

http://cumminsfiltration-stg.bitnamiapp.com/optiair

optiair

http://cumminsfiltration-stg.bitnamiapp.com/fr/sitemap

sitemap

http://cumminsfiltration-stg.bitnamiapp.com/videos

videos

http://cumminsfiltration-stg.bitnamiapp.com/eUpdate

eUpdate

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1016

1016

http://cumminsfiltration-stg.bitnamiapp.com/nanoforce

nanoforce

http://cumminsfiltration-stg.bitnamiapp.com/it/node/1019

1019

http://cumminsfiltration-stg.bitnamiapp.com/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/magnumrs

magnumrs

http://cumminsfiltration-stg.bitnamiapp.com/centrifuge

centrifuge

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilters

spinonfilters

http://cumminsfiltration-stg.bitnamiapp.com/spinonfilterlube

spinonfilterlube

http://cumminsfiltration-stg.bitnamiapp.com/es/fluidanalysis

fluidanalysis

http://cumminsfiltration-stg.bitnamiapp.com/sensors

sensors

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1272

1272

7/24/2018 QA-531 71

Page 73: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/additives

additives

http://cumminsfiltration-stg.bitnamiapp.com/de/node/2085

2085

http://cumminsfiltration-stg.bitnamiapp.com/es/literature/fuel

fuel

http://cumminsfiltration-stg.bitnamiapp.com/fr/literature/crankcase-ventilation

crankcase-ventilation

http://cumminsfiltration-stg.bitnamiapp.com/de/node/692

692

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/es/warranty

warranty

http://cumminsfiltration-stg.bitnamiapp.com/de/node/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/def

def

http://cumminsfiltration-stg.bitnamiapp.com/de/node/697

697

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/search/gss/cummins

cummins

http://cumminsfiltration-stg.bitnamiapp.com/analysis

analysis

http://cumminsfiltration-stg.bitnamiapp.com/aluminumcorrosion

aluminumcorrosion

http://cumminsfiltration-stg.bitnamiapp.com/search

search

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss/1234

1234

http://cumminsfiltration-stg.bitnamiapp.com/dieselpro

dieselpro

http://cumminsfiltration-stg.bitnamiapp.com/search/gss

gss

http://cumminsfiltration-stg.bitnamiapp.com/seapro

seapro

http://cumminsfiltration-stg.bitnamiapp.com/zh/search/gss

gss

7/24/2018 QA-531 72

Page 74: Web Application Report

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

Low

http://cumminsfiltration-stg.bitnamiapp.com/de/node/

http://cumminsfiltration-stg.bitnamiapp.com/de/search/gss/1234

1234

http://cumminsfiltration-stg.bitnamiapp.com/fr/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/fr/conventional

conventional

http://cumminsfiltration-stg.bitnamiapp.com/fr/closedcvfilters

closedcvfilters

http://cumminsfiltration-stg.bitnamiapp.com/fr/coolantfiltration

coolantfiltration

http://cumminsfiltration-stg.bitnamiapp.com/es/directflow

directflow

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/es/qualitycert

qualitycert

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

http://cumminsfiltration-stg.bitnamiapp.com/es/hybrid

hybrid

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/de/user/login

login

http://cumminsfiltration-stg.bitnamiapp.com/node

node

http://cumminsfiltration-stg.bitnamiapp.com/search/site/cummins

cummins

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/de/regions/cis

cis

http://cumminsfiltration-stg.bitnamiapp.com/fr/node

node

7/24/2018 QA-531 73

Page 75: Web Application Report

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Informational

Email Address Pattern FoundRisk: Itispossibletogathersensitiveinformationaboutthewebapplicationsuchasusernames,

passwords,machinenameand/orsensitivefilelocations

Causes: Insecurewebapplicationprogrammingorconfiguration

Fix: Removee-mailaddressesfromthewebsite

CVSS Score: 0.0

Severity URL Entity

http://cumminsfiltration-stg.bitnamiapp.com/retail-locator

retail-locator

http://cumminsfiltration-stg.bitnamiapp.com/print/792

792

http://cumminsfiltration-stg.bitnamiapp.com/print/1272

1272

http://cumminsfiltration-stg.bitnamiapp.com/print/2082

2082

http://cumminsfiltration-stg.bitnamiapp.com/print/2077

2077

http://cumminsfiltration-stg.bitnamiapp.com/print/699

699

http://cumminsfiltration-stg.bitnamiapp.com/print/1060

1060

http://cumminsfiltration-stg.bitnamiapp.com/print/692

692

http://cumminsfiltration-stg.bitnamiapp.com/print/1276

1276

http://cumminsfiltration-stg.bitnamiapp.com/print/688

688

http://cumminsfiltration-stg.bitnamiapp.com/fr/print/1771

1771

http://cumminsfiltration-stg.bitnamiapp.com/print/1163

1163

http://cumminsfiltration-stg.bitnamiapp.com/print/

http://cumminsfiltration-stg.bitnamiapp.com/print/773

773

http://cumminsfiltration-stg.bitnamiapp.com/print/2725

2725

http://cumminsfiltration-stg.bitnamiapp.com/print/1273

1273

http://cumminsfiltration-stg.bitnamiapp.com/print/2724

2724

http://cumminsfiltration-stg.bitnamiapp.com/print/774

774

7/24/2018 QA-531 74

Page 76: Web Application Report

Informational

Informational

Informational

Informational

http://cumminsfiltration-stg.bitnamiapp.com/print/772

772

http://cumminsfiltration-stg.bitnamiapp.com/print/976

976

http://cumminsfiltration-stg.bitnamiapp.com/print/customerassistance_us

customerassistance_us

http://cumminsfiltration-stg.bitnamiapp.com/sites/all/modules/encrypt_submissions/jcryption/jquery.jcryption.js

jquery.jcryption.js

A10-InsufficientLoggingandMonitoring 0

7/24/2018 QA-531 75