PrestaShop Forum

The best place in the world to ask questions about PrestaShop and get advice from our passionate community!

PrestaShop Forum

Jump to content

 

script vulnerable to Cross Site Scripting (XSS) attacks

4 replies to this topic
#1
wiros

    PrestaShop Apprentice

  • Members
  • PipPip
  • 37 posts
Hi,

It seems I had a hack attack last week. The site was down for two days when I found out that that the permisions of some files and folders had been changed. Also the hosting company told me that some PHP script are unsafe so usPHP refuse to run the sripts
I ran acunetix myself and program gave we 35 scipts that are possibility vulnerable to Cross Site Scripting (XSS) attacks.

Anyone has this experience and can tell me how to secure the scripts?

Thanks, Robert

#2
Rémi Gaillard

    PrestaShop Apprentice

  • PrestaTeam
  • 193 posts
Hi,

What is your version of Prestashop ?
Rémi GaillardPrestaBox ManagerPrestashop







Help PrestaShop, make a donation !

#3
Paul C

    PrestaShop Fanatic

  • Members
  • PipPipPipPip
  • 1005 posts
Hmm. So are you saying that you think Prestashop is vulnerable, or are you saying that now your site has been hacked there are now 35 scripts that may be vulnerable to XSS?

I'm not sure what you've actually tested here.

Paul
Free Prestashop modules and developer resources

Latest Prestashop Developer articles:
* 1.4 Plugins Revisited – Part 1
* 1.4 Plugins Revisited – Part 2

Latest News:
Prestashop Module and Theme Developers can now Advertise on eCartService.net

#4
Rémi Gaillard

    PrestaShop Apprentice

  • PrestaTeam
  • 193 posts
In PrestaShop 1.2.5 we have fixed some XSS on front office.

Regards,
Rémi GaillardPrestaBox ManagerPrestashop







Help PrestaShop, make a donation !

#5
wiros

    PrestaShop Apprentice

  • Members
  • PipPip
  • 37 posts
I use Version 1.2.5.0 - 0.212s at the moment.

Greeting, Robert
www.accu-company.nl