Zen Cart Logo
Forums / Reports of Security Problems / our Web server is vulnerable to cross-site scripting attacks Number 2

our Web server is vulnerable to cross-site scripting attacks Number 2

Views: 60

Results 1 to 11 of 11
31 Mar 2012, 17:10
#1
johnnycopilot avatar

johnnycopilot

Zen Follower

Join Date:
Mar 2012
Posts:
325
Plugin Contributions:
0

our Web server is vulnerable to cross-site scripting attacks Number 2

Here is my 2nd warning. I'm not sure if it's part of the same warning or not. Here's what the report says. Like I said, any help in resolving these 2 issues would be greatly appreciated!!

Port: http (80/tcp)
Description:
Your website contains pages that do not properly sanitize visitor‑provided input to make sure it contains no malicious content or scripts. Cross‑site scripting vulnerabilities let malicious users execute arbitrary HTML or script code in another visitor'
s browser
Risk Factor:
Medium / CVSS Base Score : 4.3(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)

Solution:
Restrict access to the vulnerable application. Contact the vendor for a patch or upgrade.
Output:
Using the GET HTTP method, Site Scanner found that :

  • The following resources may be vulnerable to cross-site scripting (comprehensive test) :
  • The 'products_id[583]' parameter of the /index.php CGI :
    /index.php?products_id[583]=<<<<<<<<<<foo"bar'204>>>>>
    -------- output --------
    <img id="close-pic" class="close-pic float-right" src="includes/te [...]
<ul class="list-popup"> <li><a href="/index.php?products_id[583]=<<<<<<<<<<foo"bar'204>>>>>& currency=USD">US Dollar ($)</a></li> <li><a href="/index.php?products_id[583]=<<<<<<<<<<foo"bar'204>>>> [...] <li><a href="/index.php?products_id[583]=<<<<<<<<<<foo"bar'204>>>> [...] ------------------------ Other references : CWE:79, CWE:80, CWE:81, CWE:83, CWE:20, CWE:74, CWE:442, CWE:712, CWE:722, CWE:725, CWE:811, CWE:751, CWE:801, CWE:116, CWE:692, CWE:87, CWE:85, CWE:86, CWE:84
01 Apr 2012, 08:18
#2
johnnycopilot avatar

johnnycopilot

Zen Follower

Join Date:
Mar 2012
Posts:
325
Plugin Contributions:
0

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

sorry, in the "title" it's supposed to say YOUR Web server...... , not OUR Web Server..... ,,, I didn't copy it very good....

01 Apr 2012, 13:32
#3
qdixon avatar

qdixon

Support Team

Join Date:
Feb 2004
Location:
Simcoe, Ontario, Canada
Posts:
1,906
Plugin Contributions:
1

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

This would be in reference to something you have added such as some javascript or you may have some cgi scripts running that should be eliminated. Remove the cgi bin if you are not using that.

01 Apr 2012, 16:37
#4
johnnycopilot avatar

johnnycopilot

Zen Follower

Join Date:
Mar 2012
Posts:
325
Plugin Contributions:
0

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

I have a question for you... In reference to this issue AND the other issue I had in which you told me the issue was in the template I am using ("aBagon Red"), will these issues be resolved if I do nothing once I activate my SSL? I am just building the website, and haven't activated the SSL on my server yet? Thanks!!!

01 Apr 2012, 16:54
#5
qdixon avatar

qdixon

Support Team

Join Date:
Feb 2004
Location:
Simcoe, Ontario, Canada
Posts:
1,906
Plugin Contributions:
1

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

The above PCI vulnerability has nothing to do with SSL as it is on port 80.

This has more to do with something cgi related running in conjunction with the index.php file. For instance maybe a banner or something that you may have installed to see what it did in cpanel. That is why I suggested deleting the CGI folder in the root of your website and rerunning the scan. Or this could simply be bad format in your template.

I assume you are using 1.3.9h or 1.5 correct?

01 Apr 2012, 20:52
#6
johnnycopilot avatar

johnnycopilot

Zen Follower

Join Date:
Mar 2012
Posts:
325
Plugin Contributions:
0

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

oh sorry, I should have said what I was using.. I am using v1.5.0 with abagon red template. strangely enough, the website scanning software came back clean today.. I mean, those two issues aren't there anymore. GONE.... It is saying that I have 10 "informational" issues, that I will not bore you with the details of, because they don't seem to be critical,,, the website protection scale they have is "informational - blue", "warning - orange", "critical - red", and "malware - black".. these are blue.. things like 1."Some cgis are candidate for extended injection tests." whatever that means,,, 2. "External links were discovered on your website." 3. "Pages in your website require authentication". 4."Your website does not use HTTPS to transmit passwords". . etc. etc. and even I should be able to fix those.. haha.. if I have any further problems I will try to fix first, then post here. but, like I said, the 2 WARNINGS that I got (posted in my 2 threads) are gone.. Where did they go? or actually, how did they "pass" today and not yesterday? well anyway, thanks so much for your quick response and help!! Zen Cart People so far have been absolutely fantastic....... oh, my website is stageandtheaterlighting.com thanks!!

02 Apr 2012, 16:34
#7
johnnycopilot avatar

johnnycopilot

Zen Follower

Join Date:
Mar 2012
Posts:
325
Plugin Contributions:
0

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

the warning came back, only the products_id number is different. I went to the cgi folder, and the folder is empty... am I supposed to "delete" the folder? (I use FTP so I can see it). I googled my problem and still can't seem to get it fixed. I sent godaddy a message in their help section (that is provided when you get a warning), and they did not respond. I can't find foo"bar' anywhere in my database. I know what the real "fubar" acronym means, so is this just part of the warning? or is there actually supposed to be the words foo"bar' in my database somewhere? or could it be that I installed "Lightbox" photo viewer? Any more advice would be appreciated... Here is today's warning

Risk Factor:
Medium / CVSS Base Score : 4.3(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)

Solution:
Restrict access to the vulnerable application. Contact the vendor for a patch or upgrade.

Output:
Using the GET HTTP method, Site Scanner found that :

  • The following resources may be vulnerable to cross-site scripting (comprehensive test) :
  • The 'products_id[15]' parameter of the /index.php CGI :
    /index.php?products_id[15]=<<<<<<<<<<foo"bar'204>>>>>
    -------- output --------
    <img id="close-pic" class="close-pic float-right" src="includes/te [...]
<ul class="list-popup"> <li><a href="/index.php?products_id[15]=<<<<<<<<<<foo"bar'204>>>>>&c urrency=USD">US Dollar ($)</a></li> <li><a href="/index.php?products_id[15]=<<<<<<<<<<foo"bar'204>>>>> [...] <li><a href="/index.php?products_id[15]=<<<<<<<<<<foo"bar'204>>>>> [...] ------------------------ Other references : CWE:79, CWE:80, CWE:81, CWE:83, CWE:20, CWE:74, CWE:442, CWE:712, CWE:722, CWE:725, CWE:811, CWE:751, CWE:801, CWE:116, CWE:692, CWE:87, CWE:85, CWE:86, CWE:84
02 Apr 2012, 20:29
#8
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
177

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

They're just using "foo" and "bar" as test text strings. They could have used "bill" and "fred". In the technology industry "foobar", "foo", "bar" etc are used as dummy text, very seldom is it actually representative of literal text.

04 Apr 2012, 16:41
#9
johnnycopilot avatar

johnnycopilot

Zen Follower

Join Date:
Mar 2012
Posts:
325
Plugin Contributions:
0

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

I renamed the cgi folder yesterday, and I keep getting the same 'warning' ..... do I need to delete the folder, or should renaming it have done the trick? I keep looking for answers, but I don't know what to do to get rid of the warning.. hmmm... any more help would be greatly appreciated!! Thanks!!

04 Apr 2012, 16:55
#10
qdixon avatar

qdixon

Support Team

Join Date:
Feb 2004
Location:
Simcoe, Ontario, Canada
Posts:
1,906
Plugin Contributions:
1

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

At this point the output is too vague and is too broad. Call your scanning company and speak with a scan tech. Ask them for some more detailed output and explanation.

04 Apr 2012, 17:25
#11
johnnycopilot avatar

johnnycopilot

Zen Follower

Join Date:
Mar 2012
Posts:
325
Plugin Contributions:
0

Re: our Web server is vulnerable to cross-site scripting attacks Number 2

ok will do!! And thanks for all of your help. The Zen Cart Community has been very helpful and nice!! I will not post anything else about this issue, I'm sure I will get to the bottom of it today... and once again, thanks for your time!!! :smile: