View ProjeQtOr On SourceForge.net
ProjeQtOr - Project Management Tool
Support us on Capterra
OIN - Open Invention Network
ProjeQtOr free project management software - Requests detected as attacks " cross site scripting " and " SQL injection " - ProjeQtOr
 
 

Requests detected as attacks " cross site scripting " and " SQL injection "

More
15 Jul 2019 14:21 #1 by sogeti

File Attachment:

File Name: crosssites...ing.xlsx
File Size:25 KB

File Attachment:

File Name: sqlinjection.xlsx
File Size:25 KB


Hi babynus,

We have had a few days ago a problem with our firewall, and requests used by projeqtor.
Indeed, you find in attachments all the requests detected as attacks " cross site scripting " and " SQL injection "

We have added them to a white list, but will you correct these "false" attacks in the future ?
Attachments:

Please Log in or Create an account to join the conversation.

More
15 Jul 2019 14:50 #2 by babynus
Hi,

The firewall blocked because of content of fields users entered in description and/or result...
The data contains workds that firewall interprts as XSS or SQL Injection...
We cannot do much about this (except try and encore all data inputs what would be heavy work)

Babynus
Administrator of ProjeQtOr web site

Please Log in or Create an account to join the conversation.

Moderators: babynusprotion
Time to create page: 0.030 seconds

Cookies settings

×

Functional Cookies

Ce site utilise des cookies pour assurer son bon fonctionnement et ne peuvent pas être désactivés de nos systèmes. Nous ne les utilisons pas à des fins publicitaires. Si ces cookies sont bloqués, certaines parties du site ne pourront pas fonctionner.

Session

Please login to see yours activities!

Other cookies

Ce site web utilise un certain nombre de cookies pour gérer, par exemple, les sessions utilisateurs.