StudioPress Community Forums
  StudioPress Community Forums > Forums > General Discussion
For help and support, access to your downloads, or to manage your account please log into My StudioPress.

These forums have been set to read-only so you can browse the existing topics for any questions you may have.

For general discussion on WordPress, CSS and design (NOT for support) visit the new Community Forums.
 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 10-25-2010, 01:16 PM
DCE2007 DCE2007 is offline
Registered User
Genesis Member
 
Join Date: Jan 2010
Posts: 4
Exclamation Allure theme security problem- help needed

Hi,
I have been using the Allure theme for a while now. I have recently put a security site scanner in place to scan my website for security issues. It found issues with the Allure theme. I have added the information below. Please if you would advise on what to do to correct this situation.

Thanks,
D'

Question Dispute Resolve Port: http (80/tcp)
Status:
Not yet addressed

Synopsis:
The remote web server is prone to cross-site scripting attacks.
Description:
The remote web server hosts cgi scripts that fail to adequately sanitize
request strings with malicious JavaScript. By leveraging this issue,
an attacker may be able to cause arbitrary HTML and script code
to be executed in a user's browser within the security context of the
affected site.
These XSS are likely to be 'non persistent' or 'reflected'.

See Also:
http://en.wikipedia.org/wiki/Cross_s...Non-persistent http://jeremiahgrossman.blogspot.com...-pointing.html http://projects.webappsec.org/Cross-Site+Scripting

Risk Factor:
Medium / CVSS Base Score : 4.3(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)

Solution:Restrict access to the vulnerable application. Contact the vendor
for a patch or upgrade.


Output:
Using the GET HTTP method, Site Scanner found that :
+ The following resources may be vulnerable to cross-site scripting (quick test) :
/blog/wp-content/themes/allure_20/tools/timthumb.php?src=<script>alert(4
2);</script>
-------- output --------
file not found <script>alert(42);</script>
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
WP Security Problem: MySQL Injection Schema, Dataext, and fuzzer adi General Discussion 4 08-17-2010 04:29 PM
Allure down menus problem with Safari yogamoo General Discussion 4 05-22-2010 06:20 PM
Google Analytics Problem in Allure LindsyOrr General Discussion 6 02-10-2010 05:57 AM
Streamline Theme - Possible Security Issue? lfaber General Discussion 3 08-17-2009 11:29 AM


All times are GMT -5. The time now is 04:19 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.