Results 1 to 2 of 2
  1. #1
    Join Date
    Sep 2006
    Posts
    91
    Plugin Contributions
    0

    Default PCI Compliance Failed: IlohaMail 0.8.10 contains an XSS vulnerability

    I am getting emails from Security Metrics about PCI compliance. My website has 3 failing areas. Here are the failing messages:

    1. Title: Web server vulnerability Impact: /index.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings. Risk Factor: Medium/ CVSS2 Base Score: 5.0


    2. Title: Web server vulnerability Impact: /webmail/blank.html: IlohaMail 0.8.10 contains an XSS vulnerability. Previous versions contain other non-descript vulnerabilities. Risk Factor: Medium/ CVSS2 Base Score: 4.0
    3. Title: Web server vulnerability Impact: /IlohaMail/blank.html: IlohaMail 0.8.10 contains a XSS vulnerability. Previous versions contain other non-descript vulnerabilities. Risk Factor: Medium/ CVSS2 Base Score: 4.0


    Please help, Thank you so much.

  2. #2
    Join Date
    Jan 2007
    Location
    Australia
    Posts
    6,167
    Plugin Contributions
    7

    Default Re: PCI Compliance Failed

    Quote Originally Posted by yenmax View Post
    2. Title: Web server vulnerability Impact: /webmail/blank.html: IlohaMail 0.8.10 contains an XSS vulnerability. Previous versions contain other non-descript vulnerabilities. Risk Factor: Medium/ CVSS2 Base Score: 4.0
    3. Title: Web server vulnerability Impact: /IlohaMail/blank.html: IlohaMail 0.8.10 contains a XSS vulnerability. Previous versions contain other non-descript vulnerabilities. Risk Factor: Medium/ CVSS2 Base Score: 4.0
    Please help, Thank you so much.

    Yours is not a ZenCart issue. The problem is with /IlohaMail/ and /webmail/

    Cheers
    Rod

 

 

Similar Threads

  1. XSS Vulnerability in v1.3.7
    By wilt in forum Zen Cart Release Announcements
    Replies: 1
    Last Post: 24 Apr 2007, 09:54 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR