Ecommerce software home
Shopping Cart Software Forum for Ecommerce Templates
 
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

Find us on Facebook Follow us on Twitter View our YouTube channel
Search our site
Forum Search
Google Site Search
Author « Topic »  

tommieboyz
Advanced Member

128 Posts

Pre-sales questions only
(More Details...)

Posted - 06/21/2018 :  11:36:29  
I have two sites that accept CC and must be PCI compliant. they just informed me that we are failing three issues. Anyone know hot resolve.
Here they are:
CGI Generic XML Injection. A CGI application hosted on the remote web server is potentially prone to an XML injection attack.
Web Server Uses Basic Authentication Without HTTPS. The remote web server seems to transmit credentials in cleartext.
Web Server Transmits Cleartext Credentials. The remote web server might transmit credentials in cleartext.

site: metalmarkingmachines.com

Andy
ECT Moderator

95440 Posts

Posted - 06/21/2018 :  11:49:41  
Hi

Those appear to be server related rather than anything in the software. Can you pass that onto your host and see if they can sort it out for you?

Andy

Please feel free to review / rate our software

tommieboyz
Advanced Member

128 Posts

Pre-sales questions only
(More Details...)

Posted - 06/21/2018 :  11:51:07  
Thanks Andy. I did already and of course they said it was software related. I will go back to them now. I will keep you informed.

tommieboyz
Advanced Member

128 Posts

Pre-sales questions only
(More Details...)

Posted - 06/21/2018 :  12:44:57  
Andy,
What is the folder assets for in this string? Is it needed for running ECT?
URL : https://www.dogtagmachines.com/assets/js/vendor/jquery-1.10.2.min.js

Installed version : 1.10.2 Fixed version : 1.12.0

Andy
ECT Moderator

95440 Posts

Posted - 06/21/2018 :  13:30:33  
You can download a more recent version here https://jquery.com/download/

or change the reference on your pages to

<script src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>

Andy

Please feel free to review / rate our software

Vince
Administrator

42874 Posts

Posted - 06/22/2018 :  01:58:49  
Hi Tommieboyz
For this issue...
quote:
A CGI application hosted on the remote web server is potentially prone to an XML injection attack.
Do you have any more information, such as an example URL? If so, can you send it to my email (vince AT ecommercetemplates DOT com).

Vince

Click Here for Shopping Cart Software
Click Here to sign up for our newsletter
Click Here for the latest updater

tommieboyz
Advanced Member

128 Posts

Pre-sales questions only
(More Details...)

Posted - 06/22/2018 :  07:53:46  
Thanks Vince. I just sent the info.
  « Topic »  
Jump To:
Shopping Cart Software Forum for Ecommerce Templates © 2002-2022 ecommercetemplates.com
This page was generated in 0.02 seconds. Snitz Forums 2000