• Resolved MaBuSalmonWatch

    (@mabusalmonwatch)


    Scan by SiteLock brings up this critical msg – is it something we need to be worried about or did the version numbering change causing a false positive? Thanks.

    DOWNLOAD-MONITOR 1.9.5
    Download Monitor 3.3.5.4 – Authenticated Cross-Site Scripting (XSS)
    Authenticated Cross-Site Scripting (XSS) in Download Monitor, before at least version 3.3.5.4, can be used by attackers to place arbitrary JavaScript in to a URL or link through the download-monitor/uploader.php file. Note: This plugin has changed its version numbering, this may produce false positives.

    DOWNLOAD-MONITOR 1.9.5
    Download Monitor 3.3.5.7 – index.php dlsearch Parameter XSS (Note: This plugin changed its version numbering, this may produce false positive)
    Authenticated Cross-Site Scripting (XSS) in Download Monitor before version 3.3.5.9 can be used by authenticated attackers to place arbitrary JavaScript in to a URL or link through the index.php file. The attack is executed through the ‘dlsearch’ parameter. Note: The versioning of this plugin was changed, so this detection may produce false positives.

The topic ‘Plugin changed version numbering, may produce false positives-security scan’ is closed to new replies.