Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Cross-Site Scripting Security Scan Failure / PCI ComplianceCross-Site Scripting Security Scan Failure / PCI Compliance
Previous
 
Next
New Post
12/10/2012 1:49 PM
 

I just got off the phone with a guy at ControlScan, as my website didn't pass a security scan due to a lot of cross-site scripting failures.

The Scan was required they said as part of a new PCI compliance for Authorize.net and my account with Merchant Warehouse.

He said there should be a plug-in for this, but that DotNetNuke was very vulnerable to this as a platform. 

I am running DNN 6.2.3 and being hosted through PowerDNN, and so I am very surprised this is an issue. Any recommendations?

 
New Post
12/11/2012 3:21 AM
 
I suggest upgrading to 6.2.5, there might have been an issue. However, DNN is usually carefully checking all security risks within the platform, however any 3rd party module will not be covered and need to be checked separately. you need to review details of the report to identify, which component is claimed to contain the risky parts.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
12/11/2012 3:21 AM
 
PS: please contact security (at) dotnetnuke.com for any related platform issues being reported.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
12/16/2012 12:47 AM
 
as Sebastian said, please send the details to security@dotnetnuke.com - please be aware that many automated scans produce "false-positives" i.e. list issues that are not valid. DotNetNuke has extensive defence-in-depth including code to protect against common cross-site scripting attempts.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
12/19/2012 6:46 PM
 

Thank you for the info. I did upgrade to  6.2.5, and so I will have them re-scan and let you know. 

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Cross-Site Scripting Security Scan Failure / PCI ComplianceCross-Site Scripting Security Scan Failure / PCI Compliance


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out