osCmax v2.5 User Manual
Results 1 to 3 of 3

Whos online Vunerability Fix

This is a discussion on Whos online Vunerability Fix within the New osCommerce Contributions forums, part of the osCommerce 2.2 Forums category; Found a security issue in catalog/includes/functions/whos_online.php line 30: $wo_last_page_url = getenv('REQUEST_URI'); Replace with: $wo_last_page_url = htmlspecialchars(getenv('REQUEST_URI')); This XSS Vulnerability affects ...

      
  1. #1
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,907
    Rep Power
    568


    Post Whos online Vunerability Fix

    Found a security issue in catalog/includes/functions/whos_online.php

    line 30:
    $wo_last_page_url = getenv('REQUEST_URI');

    Replace with:
    $wo_last_page_url = htmlspecialchars(getenv('REQUEST_URI'));


    This XSS Vulnerability affects the adminpanel->Whos online

    a hacker could easily grab your admin cookie.

    More...
    Michael Sasek
    osCMax Developer


    osCmax Installation Service
    - Have our professionals install osCmax on your server - same day service!
    osCmax 2.5 User Manual - the must have beginners guide to osCmax v2.5

    Stay Up To Date with everything osCMax:
    Free osCmax Newsletters - Security notices, New Releases, osCMax News
    osCmax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  2. #2
    New Member
    Join Date
    Dec 2008
    Posts
    19
    Rep Power
    0


    Default Re: Whos online Vunerability Fix

    Thanks- applied new code. Works fine.

  3. #3
    Active Member
    Join Date
    Jun 2008
    Posts
    195
    Rep Power
    4


    Default Re: Whos online Vunerability Fix

    Same here, thank-you Michael

Similar Threads

  1. Whos Online Enhancement
    By michael_s in forum New osCommerce Contributions
    Replies: 0
    Last Post: 10-18-2008, 08:00 AM
  2. Identify Search Engine Bots in "Whos Online"
    By michael_s in forum New osCommerce Contributions
    Replies: 0
    Last Post: 11-27-2007, 01:21 PM
  3. whos online problem
    By jschafer52 in forum osCmax v2 Customization/Mods
    Replies: 3
    Last Post: 11-11-2007, 10:52 AM
  4. Whos Online Without Search Engines
    By michael_s in forum New osCommerce Contributions
    Replies: 0
    Last Post: 02-11-2007, 01:00 PM
  5. Whos Online Without Search Engines
    By michael_s in forum New osCommerce Contributions
    Replies: 0
    Last Post: 02-11-2007, 11:51 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •