<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>ProductCart Shopping Cart Software Forums : PCI - Cross-Site Scripting</title>
  <link>https://forum.productcart.com/</link>
  <description><![CDATA[This is an XML content feed of; ProductCart Shopping Cart Software Forums : Using ProductCart : PCI - Cross-Site Scripting]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sat, 11 Apr 2026 00:51:09 +0000</pubDate>
  <lastBuildDate>Thu, 31 Jul 2014 12:24:42 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forum.productcart.com/RSS_post_feed.asp?TID=5914</WebWizForums:feedURL>
  <image>
   <title><![CDATA[ProductCart Shopping Cart Software Forums]]></title>
   <url>https://forum.productcart.com/forum_images/pc_logo_50.png</url>
   <link>https://forum.productcart.com/</link>
  </image>
  <item>
   <title><![CDATA[PCI - Cross-Site Scripting : We&amp;#039;re running 4.5bMs SP 1.The...]]></title>
   <link>https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22160.html#22160</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=126">steverguy</a><br /><strong>Subject:</strong> 5914<br /><strong>Posted:</strong> 31-July-2014 at 12:24pm<br /><br />We're running 4.5bMs SP 1.<div><br></div><div>The PCI vendor is Control Scan</div><div><br></div><div>We're hoping to upgrade to 5.0 in the next couple of months, but we have a lot of customized code (not on viewcategories.asp) - &nbsp;so we haven't jumped to 4.7 yet.</div>]]>
   </description>
   <pubDate>Thu, 31 Jul 2014 12:24:42 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22160.html#22160</guid>
  </item> 
  <item>
   <title><![CDATA[PCI - Cross-Site Scripting : PCI scans are a total moving target....]]></title>
   <link>https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22159.html#22159</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=290">Greg Dinger</a><br /><strong>Subject:</strong> 5914<br /><strong>Posted:</strong> 31-July-2014 at 12:20pm<br /><br /><p>PCI scans are a total moving target.&nbsp; You never know what they are going to scan for next.</p><p>What PCI vendor was this please?&nbsp; And what version are you running?</p><p><br></p>]]>
   </description>
   <pubDate>Thu, 31 Jul 2014 12:20:08 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22159.html#22159</guid>
  </item> 
  <item>
   <title><![CDATA[PCI - Cross-Site Scripting : Yeah, I&amp;#039;m not sure why we&amp;#039;ve...]]></title>
   <link>https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22158.html#22158</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=126">steverguy</a><br /><strong>Subject:</strong> 5914<br /><strong>Posted:</strong> 31-July-2014 at 12:17pm<br /><br />Yeah, I'm not sure why we've passed all this time and are just failing now. &nbsp; I'll submit a ticket and see what the peeps at NSC say. &nbsp;Thanks for your quick reply!<span style="font-size:10px"><br /><br />Edited by steverguy - 31-July-2014 at 12:18pm</span>]]>
   </description>
   <pubDate>Thu, 31 Jul 2014 12:17:45 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22158.html#22158</guid>
  </item> 
  <item>
   <title><![CDATA[PCI - Cross-Site Scripting :  I believe this is a known issue,...]]></title>
   <link>https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22157.html#22157</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=290">Greg Dinger</a><br /><strong>Subject:</strong> 5914<br /><strong>Posted:</strong> 31-July-2014 at 12:15pm<br /><br />I believe this is a known issue, that NSC has been able to argue successfully against the veracity of some of these vulnerability claims, and are working on 4.7 SP1 in order to address the remaining concerns.&nbsp; Cedric may want to respond in greater detail.&nbsp; I'd like to know what PCI compliance company this came from, and suggest that you do submit it to support.]]>
   </description>
   <pubDate>Thu, 31 Jul 2014 12:15:28 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22157.html#22157</guid>
  </item> 
  <item>
   <title><![CDATA[PCI - Cross-Site Scripting : I got an PCI failure for Cross-Site...]]></title>
   <link>https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22156.html#22156</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=126">steverguy</a><br /><strong>Subject:</strong> 5914<br /><strong>Posted:</strong> 31-July-2014 at 12:09pm<br /><br />I got an PCI failure for Cross-Site Scripting vulnerability during our scan yesterday. &nbsp;It was on viewcategories.asp - a page I haven't done any customization on.<div><br></div><div>It appears that they (the PCI company) test by adding&nbsp;<span style="color: rgb53, 53, 53; line-height: 19px;">a small javascript alert funtion to the querystring. &nbsp;When I test this using the exact url they use, I get a techerr.asp page, and the error gets logged to the database. &nbsp;The script doesn't get run as far as I can tell (no alert box popped up), but the error that's logged is a type=mismatch.</span></div><div><font color="#353535"><span style="line-height: 19px;"><br></span></font></div><div><font color="#353535"><span style="line-height: 19px;">Is this how ProductCart should respond to such an attack?</span></font></div><div><font color="#353535"><span style="line-height: 19px;"><br></span></font></div><div><font color="#353535"><span style="line-height: 19px;">I didn't want to submit a support ticket if this is the way it's supposed to work.</span></font></div><div><font color="#353535"><span style="line-height: 19px;"><br></span></font></div><div><font color="#353535"><span style="line-height: 19px;">Thanks!<br></span></font><div><br></div><div><br></div></div>]]>
   </description>
   <pubDate>Thu, 31 Jul 2014 12:09:35 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/pci-crosssite-scripting_topic5914_post22156.html#22156</guid>
  </item> 
 </channel>
</rss>