Hi Kelly,
While I'm sure there are myriad vulnerabilities in the CMS I'm not sure why it matters. The CMS is an internal-use tool - it is protected by your corporate firewalls and policies; it is not public-facing as is de rigueur with many CMS these days. Therefore, it is at minimum risk of attack, since it would have to have come from inside the corporate network. One might think that if one could compromise the internal network there would be bigger prizes than the CMS or the website, no? Or have I entirely missed the point?? Rgds, Richard H. From: reddot-cms-users@googlegroups.com [mailto:reddot-cms-users@googlegroups.com] On Behalf Of Kelly Burns Sent: Tuesday, 18 September 2012 12:35 AM To: reddot-cms-users@googlegroups.com Subject: XSS security vulnerability - anyone found a workaround yet? Hi guys - I am sure somebody has run into this before; but I am at a complete "dead end" here and need to resolve before our upcoming IT Audit. :( Our IT Audit firm found our Web Site Management Server 10.1 SP2 (with SQL 2008 db) poses a "significant security risk", in that it allows cross site scripting (aka "XSS") to occur in the classic ASP portions of the app. Obviously I need to correct this before our *next* audit (next month). Last September, when the audit found this info, I submitted this as a ticket for resolution to OpenText Support. They said they would forward the issue to development for analysis (this was a year ago). I realized I'd not heard back from them on this issue & checked back on it this week. The response was: "This ticket was linked to a BUG ID: WSGMS-8216 currently there is no resolution or much analysis on the issue, but it is now tracked by OpenText and you can always use the aforementioned ID to track its status." I searched all over OpenText KB for the bug, but it is not even listed anyplace that I could find. I was hoping that surely somebody has had the same issue and posted a workaround somewhere by now. :-( Well if it exists, I still haven't found it! Has anyone else dealt with this?? If what if anything did you do to secure RedDot properly? Thanks in Advance! Kelly -- You received this message because you are subscribed to the Google Groups "RedDot CMS Users" group. To view this discussion on the web visit https://groups.google.com/d/msg/reddot-cms-users/-/oc1eLUNtT2UJ. To post to this group, send email to reddot-cms-users@googlegroups.com <mailto:reddot-cms-users@googlegroups.com> . To unsubscribe from this group, send email to reddot-cms-users+unsubscr...@googlegroups.com <mailto:reddot-cms-users+unsubscr...@googlegroups.com> . For more options, visit this group at http://groups.google.com/group/reddot-cms-users?hl=en. -- You received this message because you are subscribed to the Google Groups "RedDot CMS Users" group. To post to this group, send email to reddot-cms-users@googlegroups.com. To unsubscribe from this group, send email to reddot-cms-users+unsubscr...@googlegroups.com. For more options, visit this group at http://groups.google.com/group/reddot-cms-users?hl=en.