Results 1 to 6 of 6
  1. #1
    Join Date
    Jun 2009
    Posts
    187
    Plugin Contributions
    0

    Default Cross site scripting zj silver

    Trying to be PCI compliant and failing... There's about 10 of these that all seem to be advanced search related.

    Any idea how I can fix?

    Thanks

    Path /shop/index.php
    Query main_page=advanced_search_result
    search_in_description=1
    keyword=x
    inc_subcat=0
    >"><script>alert(123)</script><"=20a
    alpha_filter_id=65
    Headers Referer=http%3A%2F%2F2Fshop%2Findex.php%3Fmain_page%3Dadvanced_search_result%26s earch_in_description%3D1%26keyword%3Dx+%26+ls+-l+%26+dir+%26

  2. #2
    Join Date
    Jun 2009
    Posts
    187
    Plugin Contributions
    0

    Default Re: Cross site scripting zj silver

    Any ideas?

  3. #3
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,755
    Plugin Contributions
    9

    Default Re: Cross site scripting zj silver

    Please add more detail about your issue...
    If a zjsilver issue as posted why is this in the ZenCart bug area?
    Zen-Venom Get Bitten

  4. #4
    Join Date
    Jun 2009
    Posts
    187
    Plugin Contributions
    0

    Default Re: Cross site scripting zj silver

    I posted it in the zj silver thread. I get the errors for the search form. When the customer searches for products there is an issue with cross site scripting according to mcafee.

  5. #5
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Cross site scripting zj silver

    Are you saying that the problem is isolated to just the zj-silver template? If so, then the discussion needs to happen in that template's support thread, and not in the general Zen Cart Bug Reports area.

    Additionally, have you applied this fix? http://www.zen-cart.com/forum/showthread.php?t=130701
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #6
    Join Date
    Jun 2009
    Posts
    187
    Plugin Contributions
    0

    Default Re: Cross site scripting zj silver

    I applied that patch and I still fail the PCI. So I'm not sure if its ZJ Silver or not. But thanks for the recommendation. I did apply it.

 

 

Similar Threads

  1. [Done 1.3.7.1] Cross-Site Scripting in 1.3.7
    By avansant in forum Bug Reports
    Replies: 5
    Last Post: 24 Apr 2007, 09:55 PM
  2. Replies: 1
    Last Post: 29 Sep 2006, 07:08 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg