CWE 89 Improper Neutralization of Special Elements used' flaws

Hi, A recent dynamic scan on our web applications has revealed  

 CWE 89 Improper Neutralization of Special Elements used' flaws

 

However, These errors are reported on the rendered web controls. Examples below ctl00$PageButtons, ctl00$HtmlBody$MessageText. Can you please advise if these are false positives and if not, what can be done to address these.

 

Many thanks in advance

With regards,

Dennis.


  • mroberson (Veracode, Inc.)

    Hi Dennis,

     

    Thank you for your question about your Veracode Dynamic Analysis results. If you have access to the Veracode platform, I would recommend looking there for more details about your findings. On the platform, you will be able to see the actual HTTP requests and responses made to your application by Dynamic Analysis as well as more detailed descriptions of the flaws. This should help you make a better determination about the accuracy of the findings. For CWE-89, if Dynamic Analysis submits values to your application via HTTP (i.e. via web controls in a page, URL query parameters, etc.) and receives what appear to be SQL errors in the response, that is typically strong evidence that the finding is legitimate. Since Veracode Community is a public forum, I would recommend scheduling a consultation call with a member of our Application Security Consulting team if you would like to discuss specific flaws in detail. You can schedule a consultation call by clicking on the icon in the upper-right hand corner and selecting "Contact Support". Please let us know if you have any additional questions of if there is anything else we can do to help.

     

    Best regards,

     

    Michael Roberson

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.