Possible Insecure Reflected Content Detected on Target Web Application
Netsparker detected that the target web application reflected a piece of content starting from the first byte of the response. This might cause security issues such as Rosetta Stone Attack.
An attacker might bypass same origin policy and use website to his or her advantage. Rosetta Flash is a known vulnerability which uses this technique making a victim perform arbitrary requests to the domain with the vulnerable endpoint and exfiltrate potentially sensitive data.
Actions to Take
Action might vary depending on the use of this page. This is reported just for your attention. If you concern about security and this page is used to provide data via JSONP callback function,
attribute can be returned to mitigate a possible attack:
Content-Disposition: attachment; filename=f.txt