Zen Follower
- Join Date:
- Mar 2012
- Posts:
- 325
- Plugin Contributions:
- 0
our Web server is vulnerable to cross-site scripting attacks Number 2
Here is my 2nd warning. I'm not sure if it's part of the same warning or not. Here's what the report says. Like I said, any help in resolving these 2 issues would be greatly appreciated!!
Port: http (80/tcp)
Description:
Your website contains pages that do not properly sanitize visitor‑provided input to make sure it contains no malicious content or scripts. Cross‑site scripting vulnerabilities let malicious users execute arbitrary HTML or script code in another visitor'
s browser
Risk Factor:
Medium / CVSS Base Score : 4.3(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
Solution:
Restrict access to the vulnerable application. Contact the vendor for a patch or upgrade.
Output:
Using the GET HTTP method, Site Scanner found that :
- The following resources may be vulnerable to cross-site scripting (comprehensive test) :
- The 'products_id[583]' parameter of the /index.php CGI :
/index.php?products_id[583]=<<<<<<<<<<foo"bar'204>>>>>
-------- output --------
<img id="close-pic" class="close-pic float-right" src="includes/te [...]