Scan of my site by the hosting provide reports a Medium cross-site scripting vulnerability. I am attaching the complete report as a file. Here is the summary
Description:
The remote web server hosts one or more cgi scripts that fail to
adequately sanitize request strings with malicious JavaScript. By
leveraging this issue, an attacker may be able to cause arbitrary HTML
and script code to be executed in a user's browser within the security
context of the affected site. These XSS vulnerabilities are likely to
be 'non-persistent' or 'reflected'.
See Also:
http://en.wikipedia.org/wiki/Cross_site_scripting#Non-persistent
http://www.Site Scanner.org/u?9717ad85
http://projects.webappsec.org/Cross-Site+Scripting
Risk Factor:
Medium / CVSS Base Score : 4.3 (CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
Solution:
Restrict access to the vulnerable application. Contact the vendor
for a patch or upgrade.
Can you please advice.
Thanks
| Comment | File | Size | Author |
|---|---|---|---|
| X-site-report.txt | 3.95 KB | novice |
Comments
Comment #0.0
damien tournoud commentedUnpublished security report.
Comment #1
damien tournoud commentedThis is apparently an issue in Ubercart advanced catalog. Cleared by the security team to be handled publicly, as there is no stable release of this module.
Comment #2
novice commentedFor now I have put a fix as below. Can you please review
Comment #3
mogtofu33 commentedThis security issue has been fixed on next dev snapshot (December 13, 2011)
Regards.
Mog.