User login
Recent blog posts
- Poor server performance when runing a Drupal site & Flash
- Adding files that begin with a hyphen or dash to Subversion (SVN)
- XML Sitemap Quirks and Module Weight
- May Florida Drupal Meeting
- Firefox 2.x + Mac SWFObject Workaround (White Screen Fix)
- Step by Step guilde to installing the Drupal module Google Analytics
- Drupal Hack Attacks
- Step by step guide to installing the Drupal module Find URL Alias
- Step by Step guide to installing the Drupal module Global Redirect
- Drupal Module: SEO Checklist
vulenerabilities claim
I got an email saying that there are vulenerabilities with the script. I am running the lastest version and don't believe there claim. Just wanted you to see their claim and to let me know if it is an issue. I am including the person information if you wish to ask questions from them. Thanks for a great product and look forward to your answer.
Email----
As we tested your site, it turns out that there are field in your web site pages from which some can execute scripts.
These are the steps we took to discover these vulenerabilities:
From the Contact Us page, we manipulated the source code to show a hidden input field (name = required, value = email). In that field, we inserted a harmless script: alert(document.domain)
We then clicked submit and the script was executed (you should see a small alert window with the domain name).
We found that issue in the info request page as well.
What you need to do is to make sure that all the input fields, hidden or not, are sanitized before being executed. What that means is the you
replace characters, such as < > " ' and - with their hex representation, or remove them all together so that there is no possibility of a
malicious script being executed that can compromise your customers' private information or their system.
Once you think you have sanitized the website input fields, run another scan. If all the fields are sanitized, you should get a passing scan.
Let us know if you have any further questions.
--
Daniel Rodriguez
SecurityMetrics
Technical Support
801.705.5700 Support
801.724.9600 Main
801.724.9700 fax
0207.993.8031 UK Support
www.securitymetrics.com
Thank you for the
Thank you for the information. I've emailed the company and am awaiting a reply. In the meantime could you email me the address of your form and formmail.php please. The email is my name with out the M at boaddrink dot com.
-Andrew M Riley
Did you get the information
Did you get the information that I sent you and do you have any word on this?
The company you listed has
The company you listed has not replied yet so i'm going to have to do this the hard way...
-Andrew
How are you doing on it?
How are you doing on it?
Any word on if there is any
Any word on if there is any issues with this?
Is there any issues with
Is there any issues with this? I am have people asking if they should not use it any more.
I've received the
I've received the information from the company and will be testing it.
How are you doing on
How are you doing on this?
Thanks for taking the time.