"The anti-clickjacking X-Frame-Options header is not present."

Discussion in 'Apache' started by postcd, Nov 23, 2015.

  1. #1
    Hello,

    "Nikto", Linux website security software told me:

    "The anti-clickjacking X-Frame-Options header is not present."

    im curious if anyone can explain how serious is this issue? What harm it can cause if i do not fix it?

    Per this article i see it can cause my site be displayed in an iframe of someone elses domain if im right. But how this can be harmfull?
     
    Last edited: Nov 23, 2015
    postcd, Nov 23, 2015 IP