Find Jobs
Hire Freelancers

PCI Compliance Scan Fix (Cross-Site Scripting (XSS) Vulnerability) -- 2

$10-30 USD

Închis
Data postării: peste 9 ani în urmă

$10-30 USD

Plata la predare
Hello, I need help with fixing three items from a failed PCI Compliance Scan. All three items are concerned with "Reflected Cross-Site Scripting (XSS) Vulnerability". Here´s an extract from the PCI Compliance Report from Trustwave: ######################## Port: tcp/80 A reflected cross-site scripting vulnerability was identified in this web application. Reflected cross-site scripting is when HTML or Javascript content is supplied to a user defined parameter to have it then displayed (aka: reflected) back to the user and rendered or interpreted by their browser. This web site responded to a harmless web request that included Javascript/HTML which was reflected back, indicating that the underlying web application may be vulnerable to being used in a cross-site scripting (XSS) attack. While this vulnerability does not exploit the web server itself, it can be utilized by an attacker to target end-users and potentially take over their sessions or other sensitive information. A simple proof of concept example of this would be for a user to supply "<script>alert('123')</script>" to a user defined parameter and then upon submission, a message box would pop- up for the user because the user defined content was used to modify the content of the responding page. Cross-site scripting can be found in many different forms and combinations so the full request and response that was used demonstrate this vulnerability has been provided below as evidence. All Cross-Site Scripting vulnerabilities are considered non- compliant by PCI. CVSSv2: AV:N/AC:M/Au:N/C:N/I:P/A:N Service: http ######################## For the right developer this shouldnt take too much time. But please, only bid if you can proceed. I will be able to provide more details, and the full report upon accepting an offer. Let me know if you have any questions prior to bidding.
ID-ul proiectului: 6475261

Despre proiect

4 propuneri
Proiect la distanță
Activ: 10 ani în urmă

Vrei să câștigi bani?

Avantajele de a licita pe platforma Freelancer

Stabilește bugetul și intervalul temporal
Îți primești plata pentru serviciile prestate
Evidențiază-ți propunerea
Te înregistrezi și licitezi gratuit pentru proiecte
4 freelanceri plasează o ofertă medie de $59 USD pentru proiect
Avatarul utilizatorului
Dear Sir. We claim to get it done perfectly for you EXACTLY in the way you want it - Kindly give we a chance and we will prove myself - Ready to prove our words, let's get it done right away and I mean RIGHT AWAY !! Looking forward to hear from you soon - GOD Bless You.
$74 USD în 1 zi
4,9 (97 recenzii)
6,3
6,3
Avatarul utilizatorului
Hello, XSS can occur when a user is allowed to enter some input on the site and that input is not process or any check is not allowed there. First we need to check from where the attacks are done and then we need to apply the solution to fix it. Depending on the number of places we need to apply the solution , we will be able to provide appropriate quote to you. Also let us know the website URL. Thanks
$30 USD în 1 zi
5,0 (7 recenzii)
2,7
2,7

Despre client

Steagul UNITED STATES
Chisago City, United States
5,0
20
Metoda de plată a fost confirmată
Membru din mar. 15, 2012

Verificarea clientului

Mulțumim! Ți-am trimis prin e-mail linkul pe care trebuie să-l accesezi pentru a revendica creditul gratuit.
A apărut o eroare la trimiterea e-mailului. Încearcă din nou.
Utilizatori înregistrați Totalul proiectelor postate
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Se încarcă previzualizarea
S-a oferit permisiunea de depistare a locației.
Ți-a expirat sesiunea pentru conectare sau te-ai deconectat. Conectează-te din nou.