X-Content-Type-Options header missing

Disclosed: 2014-07-08 10:00:33 By jayvardhansingh To joola-io
Unknown
Vulnerability Details
Hello Team The doesn't have a header settings for X-Content-Type Options which means it is vulnerable to MIME sniffing. The only defined value, "nosniff", prevents Internet Explorer and Google Chrome from MIME-sniffing a response away from the declared content-type. This also applies to Google Chrome when downloading extensions. This reduces exposure to drive-by download attacks and sites serving user uploaded content that by clever naming could be treated by MSIE as executable or dynamic HTML files.
Actions
View on HackerOne
Report Stats
  • Report ID: 12613
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report