Loaded Commerce Community

Banner


Board index » PCI Compliance » PCI for store owners - merchants

All times are UTC - 5 hours




Post new topic Reply to topic  [ 7 posts ] 
Author Message
 Post subject: PCI / cross site scripting / advanced search / issue?
PostPosted: Tue Sep 07, 2010 7:37 pm 
Offline
CRE Talented

Joined: Thu Dec 25, 2008 5:09 pm
Posts: 489
Location: CO
Hi,

I had my scan done by trustwave and they identified an issue with cross site scripting with what seems to relate to the osCsid and the advanced search. Here is the text....

Code:
Cross-Site Scripting (XSS)
Cross-site scripting is a term used to describe problems which arise when
maliciously crafted user data causes a web application to re-direct an unsuspecting
web browser to an undesired site. It was possible to send strings with special HTML
characters ( < > " ' ) to your web application, and see them rendered in the response.
Since these characters were not encoded by the web application, it may be possible
to inject HTML scripting code into the rendered page. The injections can occur in
your HTML body, Title, Scripting, or even commented out portions of the
document. Note: Due to the potential negative impact on this web server's resources
that could result from attacking a large number of cross-site scripting attack vectors,
TrustKeeper abandons this test after it has found at least three instances where user
input is not being properly sanitized. Therefore, it is possible that the reported
findings associated with this vulnerability are only a subset of all possible attack
vectors.
All Cross-Site Scripting vulnerabilities are considered non-compliant by PCI.
CVSSv2: AV:N/AC:M/Au:N/C:N/I:P/A:N (4.3)
Reference: http://www.cert.org/advisories/CA-2000-02.html, http://www.owasp.org/
index.php/Cross-site_scripting, http://www.owasp.org/index.php/Data_Validation,
http://www.owasp.org/index.php/Review_Code_for_Cross-site_scripting
Service: Apache
Evidence:
Virtual Host: www.estore.com
Date: 2010-09-06 21:16:34.78
Vulnerable Page: http://7.105.5.3:80/store/advanced_search_result.php
HTTP Request Mode: get
HTTP Status Code: 200
Test Input String: %3CScRipT%20%3Ealert%28%27test%27%29%3B%3C%
2FScRipT%20%3E
Search Pattern:
Pattern Match:
Referrer Page: http://www.estore.com/store/big-don-c-95.html?
products_id=105&action=buy_now
Vulnerable Parameter: keywords
Vulnerable Parameter: osCsid



I am on CRELoaded Standard 6.3.3 and looking at the patch for 6.4.1 the advanced search doesn't seem to be there so I am guessing that isn't the file that might need a change.

So is this something that has a fix for it or is something that people are going to tell me "it can only be fixed by upgrading"?

Thanks!
Mike


Top
 Profile  
 
 Post subject: Re: PCI / cross site scripting / advanced search / issue?
PostPosted: Fri Sep 10, 2010 10:24 pm 
Offline
CRE Talented

Joined: Thu Dec 25, 2008 5:09 pm
Posts: 489
Location: CO
No reply? I would think if this is an issue that people would like to know and know of a fix....

Anyone?


Top
 Profile  
 
 Post subject: Re: PCI / cross site scripting / advanced search / issue?
PostPosted: Fri Sep 17, 2010 11:04 pm 
Offline
CRE Talented

Joined: Thu Dec 25, 2008 5:09 pm
Posts: 489
Location: CO
Bump.


Top
 Profile  
 
 Post subject: Re: PCI / cross site scripting / advanced search / issue?
PostPosted: Sat Sep 25, 2010 3:58 pm 
Offline
CRE Talented

Joined: Thu Dec 25, 2008 5:09 pm
Posts: 489
Location: CO
Well here it is almost 1 Oct and no one has answered. The CSS vulnerability makes so we are not PCI compliant.

So no one has an opinion?


Top
 Profile  
 
 Post subject: Re: PCI / cross site scripting / advanced search / issue?
PostPosted: Wed Nov 17, 2010 12:14 pm 
Offline
CRE Talented
User avatar

Joined: Tue Nov 30, 2004 1:00 am
Posts: 375
Location: New Smyrna Beach, FL
StrikeHawk has already been developing XSS filters for advanced search and other weaknesses in the shopping cart. 6.4.1a is in testing and we'd welcome you to monitor the issue

_________________
Inetbizo Open Source eCommerce Strategy Consulant
========================
EOS, CRE, osCommerce E-Commerce Education, Forums, Links


Top
 Profile  
 
 Post subject: Re: PCI / cross site scripting / advanced search / issue?
PostPosted: Wed Nov 17, 2010 5:12 pm 
Offline
CRE Talented

Joined: Thu Dec 25, 2008 5:09 pm
Posts: 489
Location: CO
It would be good to have a solution for 6.3.3 since I will not be "upgrading" 6.4.x


Top
 Profile  
 
 Post subject: Re: PCI / cross site scripting / advanced search / issue?
PostPosted: Sun Jan 02, 2011 1:28 am 
Offline
CRE Legend

Joined: Sun Nov 09, 2003 1:00 am
Posts: 7301
Location: Baconton, GA USA
The system we're working with installs as a module and can filter any specified GET or POST variable, as well as filtering ALL GET or POST variables, configurable from Admin.

This should work on all 6.2.12+ carts.

David

_________________
My CRE Loaded FAQ List
CRE Loaded Hosting


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

Board index » PCI Compliance » PCI for store owners - merchants

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
It is currently Thu May 24, 2012 1:56 pm
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group

Login

Forums Latest Activity

Top Listing

1. Cart2Cart - Shopping...
    Category: Shopping Cart Database Conversion Scripts
    
2. Points & Rewards PLUS!...
    Category: Add-Ons
    
3. Configuration Server...
    Category: Fixes
    
4. Credit Card with CCV
    Category: Payment Modules
    
5. CC7333_ATS
    Category: Templates
    
Show more...

© CRE Loaded is a product of Chain Reaction Ecommerce, Inc. Usage & Privacy Policy