Orckestra / C1-CMS-Foundation

C1 CMS Foundation - .NET based, open source and a bundle of joy!
https://c1.orckestra.com/
Other
251 stars 109 forks source link

Attack : OS Command Injection in Parameter #756

Open uneeshkrishnan opened 4 years ago

uneeshkrishnan commented 4 years ago

The firewall is blocking some requests from C1 Composite (Build no. 6.0.6248.33161). The firewall considers some requests as OS Command Injection in Parameter under the Injection Attacks category. Detail type="os-command-injection-strict" pattern="misc-commands-start" token="Make " Parameter="FlowUI$Document$DocumentBody$PlaceHolder0$FieldGroup1$TextBox4" value="Make a Successful Research Grant Propo"

napernik commented 4 years ago

From time to time we get some pages blocked by different firewalls, mostly in APS.NET controls related to C1 Console. We usually suggest disabling the rule in firewall, as there's nothing wrong with the product itself.