xss attack in my drupal site

Events happening in the community are now at Drupal community events on www.drupal.org.
navaneeth_r's picture

Cross site scripting report on Acunetix vulnerability scanner tool

I got the report from Acunetix tool that site have more than 50 cross site scripting possibilities through url. The tool is reporting the following urls. They are changing urls like /nodeprompt("hi") ; and reporting cross site scripting possibilities. How to solve this in Drupal. Please suggest any one. I post the fix once identified.

/_vti_bin
/content
/misc
/modules
/modules/node
/modules/system
/modules/user
/node
/sites
/sites/all
/sites/all/modules
/sites/all/modules/addthis
/sites/all/modules/cck
/sites/all/modules/cck/modules

Read more
Subscribe with RSS Syndicate content