Results 1 to 6 of 6
  1. #1
    Join Date
    Dec 2008
    Location
    USA
    Posts
    64
    Plugin Contributions
    0

    Default PCI error: Potentially Exploitable Database Error Message -- links_alias table

    I am using 1.3.8a with installed the security patch.
    I ran McAfee PCI test on the site. It reported a "Potentially Exploitable Database Error Message" error.

    Details:

    http ://www.salevalley.com/ad_click.asp/banner_id//'

    error msg on the site

    1064 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '/%' ) ORDER BY length(link_alias) DESC' at line 1
    in:
    [SELECT DISTINCT link_url, link_alias FROM links_aliases WHERE (link_alias LIKE '%/ad_click.asp/%' OR link_alias LIKE '%/banner_id/%' OR link_alias LIKE '%//%' OR link_alias LIKE '%/'/%' ) ORDER BY length(link_alias) DESC]

    Please help me to solve this.

  2. #2
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: PCI error: Potentially Exploitable Database Error Message

    Please do a search for this
    this is a false positive
    Zen cart PCI compliant Hosting

  3. #3
    Join Date
    Dec 2008
    Location
    USA
    Posts
    64
    Plugin Contributions
    0

    Default Re: PCI error: Potentially Exploitable Database Error Message -- links_alias table

    I checked on other Zencart sites. I see "404 page not found" So the problem is specific to my site. One more thing I see is my site is not going to "404" at all, if I give a random text after the domain name , instead it is going to my home page.

  4. #4
    Join Date
    Jun 2003
    Posts
    33,715
    Plugin Contributions
    0

    Default Re: PCI error: Potentially Exploitable Database Error Message -- links_alias table

    What SEO add on are you using?
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  5. #5
    Join Date
    Dec 2008
    Location
    USA
    Posts
    64
    Plugin Contributions
    0

    Default Re: PCI error: Potentially Exploitable Database Error Message

    I checked on other Zencart sites. I see "404 page not found" So the problem is specific to my site. One more thing I see is my site is not going to "404" at all, if I give a random text after the domain name , instead it is going to my home page.

  6. #6
    Join Date
    Dec 2008
    Location
    USA
    Posts
    64
    Plugin Contributions
    0

    Default Re: PCI error: Potentially Exploitable Database Error Message

    Quote Originally Posted by Kim View Post
    What SEO add on are you using?
    I am using Simple SSU URL module. I checked other sites which are using the same module and I do not see this problem..

    Looks like something I did somewhere is causing this problem.

    The heading of this post "-- links_alias table" is a cut and paste problem. which I just removed. It should be just "Re: PCI error: Potentially Exploitable Database Error Message " This is how it is shown in McAfee error report. Sorry for the confusion.

 

 

Similar Threads

  1. 500 Error - FastCGI error message after database installation page.
    By hungoveragain in forum Installing on a Windows Server
    Replies: 8
    Last Post: 24 Sep 2010, 03:37 PM
  2. Database error message???
    By A-1 Electronics in forum General Questions
    Replies: 7
    Last Post: 23 Apr 2007, 04:23 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR