Skip to main content

Cross site scripting vulnerability found in args:

More
11 years 5 months ago #197528 by jmilli
-- HikaShop version -- : HikaShop Business: 2.4.0
-- Joomla version -- : 3.4.1
-- PHP version -- : 5.3.13
-- Browser(s) name and version -- : Safari 8.04
-- Error-message(debug-mod must be tuned on) -- : Cross site scripting vulnerability found in args:Itemid

Greetings.
I just updated to Joomla 3.x from 2.5x. I have SiteLock on my site and they sent me the following message:

Cross site scripting vulnerability found in args:Itemid

The url is listed above privately.

There were 2 products listed.

After I received the message from SiteLock I upgraded HikaShop to the latest version. Is there a chance that the upgrade solved the problem? Site lock is offering to fix the problem for a fee, but I haven't looked into that yet. I am at a loss on how to fix it.

Thanks.

Please Log in or Create an account to join the conversation.

More
11 years 5 months ago #197555 by Jerome
Hi,

The "Itemid" come from Joomla itself and there is no vulnerability in that parameter which just accept a number.
So, there is nothing to do ; except generating some URL with valid itemid so the url will be right SEF and won't contain a itemid visible as parameter.

Regards,

Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Please Log in or Create an account to join the conversation.

More
11 years 5 months ago #197599 by jmilli
Hi Jerome,
Thanks for your reply. Can you provide a bit more information how to do the fix you recommend? I am not quite sure how to proceed.

Thanks.

Please Log in or Create an account to join the conversation.

More
11 years 5 months ago #197643 by Jerome
Hi,

www.ostraining.com/blog/joomla/what-is-the-joomla-itemid/
( but it's not the only article which talk about the subject )

The fix I recommend is to use a HikaShop menu when you generate links for HikaShop ; otherwise you will have a "bad" url with an itemid in the parameters.

Regards,

Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Please Log in or Create an account to join the conversation.

More
11 years 1 week ago #214670 by jmilli
Hopefully you can help. Site lock has de-authorized my site. Another url shows in front of my url when certain products are selected. I assume I need more help from a company that works with hacking, but is there anything else that I can try? Ugh.

Please Log in or Create an account to join the conversation.

More
11 years 1 week ago #214704 by nicolas
Hi,

I've checked your website but didn't see any URL issues with the products I tried.
The best, in case you've been hacked, is to contact sucuri: sucuri.net/

Please Log in or Create an account to join the conversation.

Time to create page: 0.329 seconds
Powered by Kunena Forum