Files
CyberSecurityUP e565270f43 fix: lenient finding parsing — models return confidence as words/strings
Root cause of empty results: models emit findings with confidence as a string
('High') or cvss as a number, but the Finding struct typed confidence as f64, so
serde failed the ENTIRE array on any mismatch -> 0 findings every run.

extract_findings now parses into serde_json::Value and coerces each field
(string/number/word), normalizes severity, and accepts qualitative confidence
(High->0.9 etc). Verified live: whitebox on a vulnerable sample now yields
validated findings (IDOR confirmed by vote).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 19:49:37 -03:00

89 lines
14 KiB
HTML

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<HTML>
<HEAD>
<title>acublog news</title>
<META http-equiv="Content-Type" content="text/html; charset=windows-1252">
<meta content="Microsoft Visual Studio .NET 7.1" name="GENERATOR">
<meta content="C#" name="CODE_LANGUAGE">
<meta content="JavaScript" name="vs_defaultClientScript">
<meta content="http://schemas.microsoft.com/intellisense/ie5" name="vs_targetSchema">
<LINK href="styles.css" type="text/css" rel="stylesheet">
</HEAD>
<body>
<form name="Form1" method="post" action="Default.aspx" id="Form1">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTEwNTI0MjkwNQ9kFgICAQ9kFgICAQ9kFgQCAQ8WBB4EaHJlZgUKbG9naW4uYXNweB4JaW5uZXJodG1sBQVsb2dpbmQCAw8WBB8AZB4HVmlzaWJsZWhkZArjxDMCoNA8/4bzlRmUHIna4LG5" />
</div>
<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['Form1'];
if (!theForm) {
theForm = document.Form1;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>
<div>
<input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="CA0B0334" />
<input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="/wEWVwLpus/wCAKA1c7TCAKR1ca+DAL4pI3HDAL4pI3HDAL4pOGsCQL4pOGsCQL4pJXDAgL4pJXDAgLdy+foBQLdy+foBQLdy5uPDQLdy5uPDQLdy4+iBgLdy4+iBgLdy6P5DwLdy6P5DwLdy9edBwLdy9edBwLdy8swAt3LyzAC3cv/1wkC3cv/1wkC3cuT6gIC3cuT6gIC3cvH0w8C3cvH0w8C3cv79ggC3cv79ggCttLFnwoCttLFnwoCttL5sgMCttL5sgMCttLtyQwCttLtyQwCttKB7AUCttKB7AUCttK1gw0CttK1gw0CttKppgYCttKppgYCttLd+g8CttLd+g8CttLxkQcCttLxkQcCttKl+QUCttKl+QUCttLZnQ0CttLZnQ0Ci/mrBQKL+asFAov539kJAov539kJAov58/wCAov58/wCAov555MKAov555MKAov5m7YDAov5m7YDAov5j80MAov5j80MAov5o+AFAov5o+AFAov514QNAov514QNAov5i+wLAov5i+wLAov5v4MDAov5v4MDAryT68QJAryT68QJAryTn5sBAryTn5sBAryTs74KAryTs74KAryTp9UDAryTp9UDAryT2+kMAryT2+kMAryTz4wEAryTz4wEAryT46MNAryT46MNAryTl8YGAryTl8YGAryTy68DAryTy68DTCLS2gMigbN1ehvtPSQ4g8BrKC0=" />
</div>
<TABLE id="Table1" cellSpacing="0" cellPadding="5" width="790" align="center" border="0">
<TR>
<TD style="COLOR: #e6dccf" bgColor="#806640" height="75"><a href="https://www.acunetix.com/"><IMG src="images/logo_acunetix.gif" align="absMiddle" border="0" alt="Acunetix website security"></a></TD>
<TD style="FONT-WEIGHT: bold; FONT-SIZE: small; COLOR: #e6dccf" align="right" bgColor="#806640"
height="75">Test Website for <a href="https://www.acunetix.com/vulnerability-scanner/">Acunetix Web Vulnerability Scanner</a></TD>
</TR>
</TABLE>
<TABLE id="Table2" cellSpacing="0" cellPadding="5" width="790" align="center" border="0">
<TR>
<TD class="MenuBar" style="BORDER-LEFT: #806040 1px solid"><A class="menu" title="About" href="about.aspx">about</A>
<A class="menu" title="Latest news" href="default.aspx">news</A> <a href="login.aspx" id="Mainmenu2_lnkLog" class="menu" name="lnkLog">login</a> <a href="Signup.aspx" id="Mainmenu2_lnkSignup" class="menu" name="lnkSignup">
signup</a> <A class="menu" title="Network scanner" href="https://www.acunetix.com/vulnerability-scanner/network-vulnerability-scanner/">network scanner</A>
<A class="menu" title="Network vuln help" href="https://www.acunetix.com/blog/articles/network-vulnerability-assessment-gotchas-avoid/">network vuln help</A>
</TD>
<td class="MenuBar" align="right" width="50px">
<A href="rssFeed.aspx"><IMG src="images/rss.gif" border="0"></A>
</td>
</TR>
</TABLE>
<TABLE id="Table1" cellSpacing="0" cellPadding="10" width="790" align="center" border="0">
<TR>
<TD id="tdPageData" valign="top">
<DIV class="NewsDate">posted by <strong>admin</strong> on 6/23/2026 9:16:24 PM&nbsp;<a href="Comments.aspx?id=100" class="NewsOperation">add comments</a></DIV><a href="ReadNews.aspx?id=100&NewsAd=ads/def.html" class="NewsTitle">Injected Article</a><DIV class="NewsShort">Injected via SQLi</DIV><DIV class="NewsDate">posted by <strong>admin </strong> on 5/16/2019 12:32:30 PM&nbsp;<a href="Comments.aspx?id=0" class="NewsOperation">(1) comments</a></DIV><a href="ReadNews.aspx?id=0&NewsAd=ads/def.html" class="NewsTitle">Acunetix Vulnerability Scanner Now With Network Security Scans</a><DIV class="NewsShort">Seamless OpenVAS integration now also available on Windows and Linux</DIV><DIV class="NewsDate">posted by <strong>admin </strong> on 11/8/2005 11:37:35 AM&nbsp;<a href="Comments.aspx?id=3" class="NewsOperation">add comments</a></DIV><a href="ReadNews.aspx?id=3&NewsAd=ads/def.html" class="NewsTitle">Acunetix Web Vulnerability Scanner beta released!</a><DIV class="NewsShort">26 January 2005 - A beta version of Acunetix Web Vulnerability Scanner has been released today. The beta is available for download at http://www.acunetix.com/download/.</DIV><DIV class="NewsDate">posted by <strong>admin </strong> on 11/8/2005 11:35:22 AM&nbsp;<a href="Comments.aspx?id=2" class="NewsOperation">add comments</a></DIV><a href="ReadNews.aspx?id=2&NewsAd=ads/def.html" class="NewsTitle">Web attacks - can your web applications withstand the force?</a><DIV class="NewsShort">21 July 2005 - Start-up company Acunetix released Acunetix Web Vulnerability Scanner: a tool to automatically audit website security. Acunetix Web Vulnerability Scanner 2 crawls an entire website, launches popular web attacks (SQL Injection etc.) and identifies vulnerabilities that need to be fixed.</DIV></TD>
<TD vAlign="top" width="200">
<table id="RightPanel1_Calendar" class="Calendar" cellspacing="0" cellpadding="1" title="Calendar" border="0" style="background-color:#E6DCCF;border-width:1px;border-style:Solid;font-size:X-Small;border-collapse:collapse;">
<tr><td colspan="7" style="background-color:#E6B873;"><table class="Calendar" cellspacing="0" border="0" style="font-size:X-Small;font-weight:bold;width:100%;border-collapse:collapse;">
<tr><td style="width:15%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','V9617')" style="color:Black" title="Go to the previous month">&lt;</a></td><td align="center" style="width:70%;">June 2026</td><td align="right" style="width:15%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','V9678')" style="color:Black" title="Go to the next month">&gt;</a></td></tr>
</table></td></tr><tr><th align="center" abbr="Sunday" scope="col">Sun</th><th align="center" abbr="Monday" scope="col">Mon</th><th align="center" abbr="Tuesday" scope="col">Tue</th><th align="center" abbr="Wednesday" scope="col">Wed</th><th align="center" abbr="Thursday" scope="col">Thu</th><th align="center" abbr="Friday" scope="col">Fri</th><th align="center" abbr="Saturday" scope="col">Sat</th></tr><tr><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9647')" style="color:Black" title="May 31">31</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9648')" style="color:Black" title="June 01">1</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9649')" style="color:Black" title="June 02">2</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9650')" style="color:Black" title="June 03">3</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9651')" style="color:Black" title="June 04">4</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9652')" style="color:Black" title="June 05">5</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9653')" style="color:Black" title="June 06">6</a></td></tr><tr><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9654')" style="color:Black" title="June 07">7</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9655')" style="color:Black" title="June 08">8</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9656')" style="color:Black" title="June 09">9</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9657')" style="color:Black" title="June 10">10</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9658')" style="color:Black" title="June 11">11</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9659')" style="color:Black" title="June 12">12</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9660')" style="color:Black" title="June 13">13</a></td></tr><tr><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9661')" style="color:Black" title="June 14">14</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9662')" style="color:Black" title="June 15">15</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9663')" style="color:Black" title="June 16">16</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9664')" style="color:Black" title="June 17">17</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9665')" style="color:Black" title="June 18">18</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9666')" style="color:Black" title="June 19">19</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9667')" style="color:Black" title="June 20">20</a></td></tr><tr><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9668')" style="color:Black" title="June 21">21</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9669')" style="color:Black" title="June 22">22</a></td><td align="center" style="color:#E6DCCF;background-color:#BF8630;border-color:#806640;width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9670')" style="color:#E6DCCF" title="June 23">23</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9671')" style="color:Black" title="June 24">24</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9672')" style="color:Black" title="June 25">25</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9673')" style="color:Black" title="June 26">26</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9674')" style="color:Black" title="June 27">27</a></td></tr><tr><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9675')" style="color:Black" title="June 28">28</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9676')" style="color:Black" title="June 29">29</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9677')" style="color:Black" title="June 30">30</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9678')" style="color:Black" title="July 01">1</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9679')" style="color:Black" title="July 02">2</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9680')" style="color:Black" title="July 03">3</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9681')" style="color:Black" title="July 04">4</a></td></tr><tr><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9682')" style="color:Black" title="July 05">5</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9683')" style="color:Black" title="July 06">6</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9684')" style="color:Black" title="July 07">7</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9685')" style="color:Black" title="July 08">8</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9686')" style="color:Black" title="July 09">9</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9687')" style="color:Black" title="July 10">10</a></td><td align="center" style="width:14%;"><a href="javascript:__doPostBack('RightPanel1$Calendar','9688')" style="color:Black" title="July 11">11</a></td></tr>
</table><BR>
<a href="rssFeed.aspx">Get RSS feed</a>
</TD>
</TR>
<TR>
<TD colSpan="2">
</TD>
</TR>
</TABLE>
</form>
</body>
<div style="background-color:lightgray;width:40%;margin:auto;position:absolute;left:30%;bottom:2px;text-align:center;font-size:12px;padding:1px">
<p style="padding-left:5%;padding-right:5%"><b>Warning</b>: This is not a blog. This is a test site for Acunetix. It is vulnerable to SQL Injections, Cross-site Scripting (XSS), and more. It was built using ASP.NET and it shows how bad programming leads to vulnerabilities. Do not visit the links in the comments. They are posted by malicious parties who are trying to exploit this site to their advantage. Comments are purged daily.</p>
</div>
</HTML>