Description
One or more pages contain HTML comments that look like SQL statements. These SQL statements may disclose sensitive information to an attacker. This alert may be a false positive.
Remediation
These comments should be investigated and, if necessary, removed from the pages.
References
Related Vulnerabilities
TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3806)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-7486)
Clockwork PHP dev tool enabled
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5492)