Ecommerce software home
Shopping Cart Software Forum for Ecommerce Templates
 
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

Find us on Facebook Follow us on Twitter View our YouTube channel
Search our site
Forum Search
Google Site Search
 All Forums
 Technical
 PHP (Unix / Linux / Apache) versions
 PCI Scan Fail - CGI Generic XML Injection
Author « Topic »  

John M
Advanced Member

459 Posts

Pre-sales questions only
(More Details...)

Posted - 10/06/2022 :  03:11:10  
The PCI Scan fails for the xxx.php

Title
CGI Generic XML Injection
Synopsis
A CGI application hosted on the remote web server is potentially prone to an XML injection attack.
Impact
By sending specially crafted parameters to one or more CGI scripts hosted on the remote web server, SecurityMetrics was able to get a very different response, which suggests that it may have been able to modify the behavior of the application and directly access a SOAP back-end. An attacker may be able to exploit this issue to bypass authentication, read confidential data, modify the remote database, or even take control of the remote operating system. Exploitation of XML injections is usually far from trivial. See also : http://www.nessus.org/u?5691cc8c
Resolution
Modify the affected CGI scripts so that they properly escape arguments, especially XML tags and special characters (angle brackets and slashes).
Data Received
Using the GET HTTP method, SecurityMetrics found that : + The following resources may be vulnerable to XML injection : + The 'xxx' parameter of the /xx.php CGI

John

Vince
Administrator

42874 Posts

Posted - 10/06/2022 :  03:52:58  
Hi John
I've tried all the usual injection attacks using that parameter but all seems to be fine. If you like, please send any details you have (they will often include a URL to recreate the issue for instance) to my email and I'll try on your site. But it may just be a false positive.

Vince

Click Here for Shopping Cart Software
Click Here to sign up for our newsletter
Click Here for the latest updater

John M
Advanced Member

459 Posts

Pre-sales questions only
(More Details...)

Posted - 10/06/2022 :  09:56:12  
Hi Vince,

Email sent with all the details.

Many thanks,

John

Vince
Administrator

42874 Posts

Posted - 10/07/2022 :  01:49:16  
  « Topic »  
Jump To:
Shopping Cart Software Forum for Ecommerce Templates © 2002-2022 ecommercetemplates.com
This page was generated in 0.03 seconds. Snitz Forums 2000