![]() |
|
Security Issues found by Site Scanner - Printable Version +- ZenphotoCMS Forum (https://forum.zenphoto.org) +-- Forum: Support (https://forum.zenphoto.org/forum-1.html) +--- Forum: General support (https://forum.zenphoto.org/forum-4.html) +--- Thread: Security Issues found by Site Scanner (/thread-9356.html) |
Security Issues found by Site Scanner - Takeaim - 2011-12-08 I have recently had trouble with attacks on my sites. As a result of this I transferred to a new host that had more security tools. The new host runs a process that looks at the site for vulnerabilities. The message received concerning the critical issue is When providing specially crafted parameters to your site, Site Scanner received an error from the underlying databse. The error indicates that your site might be vulnerable to SQL injection attacks. An attacker could use this vulnerability to bypass authentication, read confidential data, modify the remote database, or possibly take control of the remote server. Risk Factor: ` The website I am having problems with is I have also uploaded a document with all the issues found on my site to I really like ZenPhoto and will research all I can about making my sites more secure, but this problem is a little beyond me. Security Issues found by Site Scanner - acrylian - 2011-12-08 Thanks for the note, our chief dev sbillard will comment on these later today as well. First thoughts from me beforehand that: [list] Security Issues found by Site Scanner - sbillard - 2011-12-08 The critical issue is indeed an oversite that we will correct. 1 is not reproducable by me. The only symptom I can get from that URL is a CGI error. However, at least with PHP 5.3.5 no reflection of the URI or parameter has happened. Perhaps this is an issue for an earlier version of PHP., #3 and #4 are as acrylian has saidSecurity Issues found by Site Scanner - acrylian - 2011-12-08 We have removed the code example and link. A fix will be in the nightly build of 1.4.2 beta after tonight. |