Zen Cart Logo

Who' online

Views: 1,863

Results 1 to 6 of 6
19 Feb 2011, 1:19 AM
#1
stitchnkitty avatar

stitchnkitty

Totally Zenned

Join Date:
Jun 2009
Location:
Des Moines, Iowa USA
Posts:
618
Plugin Contributions:
0

Who' online

I just upgraded from g to h - I have run a bunch of tests and have rooted around my admin with no problems yet.

Until now:
Enter Who's Online and I get the popup.

Message from Website
struts_sa_surl_xss.nasl
Then I click OK a number of times and then it is gone.

Also I have about 213 customers in the site all the same?

Does anyone have any ideas where I might have screwed things up?
Thought I had uploaded the files meticulously.

19 Feb 2011, 2:49 PM
#2
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: Who' online

Family CGI abuses : XSS
Nessus Plugin ID 38208 (struts_sa_surl_xss.nasl)
Bugtraq ID 34686
CVE ID CVE-2008-6682

Description:

Synopsis :

The remote host is running a web application with multiple cross-site
scripting vulnerabilities.

Description :

The web application on the remote host is vulnerable to cross-site
scripting attacks. This is likely due to a vulnerable version of
Apache Struts that fails to properly encode the parameters in the
's:a' and 's:url' tags.

A remote attacker could exploit this by tricking a user into
requesting a page with arbitrary script code injected. This could
have consequences such as stolen authentication credentials.

See also :

https://issues.apache.org/jira/browse/WW-2414
https://issues.apache.org/jira/browse/WW-2427
http://www.nessus.org/u?ed70fe34

Solution :

Upgrade to Struts version 2.1.1 / 2.0.11.1 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.6
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

From this address:

http://www.nessus.org/plugins/index.php?view=single&id=38208

Vger

19 Feb 2011, 3:45 PM
#3
stitchnkitty avatar

stitchnkitty

Totally Zenned

Join Date:
Jun 2009
Location:
Des Moines, Iowa USA
Posts:
618
Plugin Contributions:
0

Re: Who' online

Oh thank you Vger
I did some checking this morning and it so happens that my scanning company was running a PCI compliance scan at the same time I was doing all my test - how is that for coincidence? Thank you for solve the issue -

20 Feb 2011, 12:13 AM
#4
rros avatar

rros

New Zenner

Join Date:
May 2010
Location:
Barendrecht, Netherlands
Posts:
20
Plugin Contributions:
0

Re: Who' online

Just so you know, you should disable the "Who's online" module because it really does contain a XSS vulnerability! I reported this on december 22th, 2010 in the "Reports of Security Problems"-forum, but no-one even responded!

20 Feb 2011, 1:16 PM
#5
vger avatar

vger

Past Contributor

Join Date:
Nov 2004
Location:
Norfolk, United Kingdom
Posts:
3,189
Plugin Contributions:
0

Re: Who' online

If people are using 1.3.9h then it should not conain any known XSS vulnerabilities. If they are still using .3.8 or earlier then of course they are in trouble.

Vger

25 Feb 2011, 1:54 AM
#6
stitchnkitty avatar

stitchnkitty

Totally Zenned

Join Date:
Jun 2009
Location:
Des Moines, Iowa USA
Posts:
618
Plugin Contributions:
0

Re: Who' online

I passed my scan with flying colors - they had an issue with the inconsistent error messages when a folder was not available but that was sovled thru my server.