![]() |
|
||||||
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi,
I have been using the Allure theme for a while now. I have recently put a security site scanner in place to scan my website for security issues. It found issues with the Allure theme. I have added the information below. Please if you would advise on what to do to correct this situation. Thanks, D' Question Dispute Resolve Port: http (80/tcp) Status: Not yet addressed Synopsis: The remote web server is prone to cross-site scripting attacks. Description: The remote web server hosts cgi scripts that fail to adequately sanitize request strings with malicious JavaScript. By leveraging this issue, an attacker may be able to cause arbitrary HTML and script code to be executed in a user's browser within the security context of the affected site. These XSS are likely to be 'non persistent' or 'reflected'. See Also: http://en.wikipedia.org/wiki/Cross_s...Non-persistent http://jeremiahgrossman.blogspot.com...-pointing.html http://projects.webappsec.org/Cross-Site+Scripting Risk Factor: Medium / CVSS Base Score : 4.3(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N) Solution:Restrict access to the vulnerable application. Contact the vendor for a patch or upgrade. Output: Using the GET HTTP method, Site Scanner found that : + The following resources may be vulnerable to cross-site scripting (quick test) : /blog/wp-content/themes/allure_20/tools/timthumb.php?src=<script>alert(4 2);</script> -------- output -------- file not found <script>alert(42);</script> |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| WP Security Problem: MySQL Injection Schema, Dataext, and fuzzer | adi | General Discussion | 4 | 08-17-2010 04:29 PM |
| Allure down menus problem with Safari | yogamoo | General Discussion | 4 | 05-22-2010 06:20 PM |
| Google Analytics Problem in Allure | LindsyOrr | General Discussion | 6 | 02-10-2010 05:57 AM |
| Streamline Theme - Possible Security Issue? | lfaber | General Discussion | 3 | 08-17-2009 11:29 AM |
© Copyright 2012 Copyblogger Media LLC · StudioPress™ is a trademark of Copyblogger Media LLC
Privacy Policy | Refund Policy | Terms of Service | Affiliate Program | Contact Us