Problem with mod_security

urs

Well-Known Member
#1
Hello

One of our server has a joomla installation with a virtuemart onlineshop.

Now we have the problem, that if we upload a picture to our store there is a 403.

In the server log:

000.000.000.000:59005-0#aqula.ch] mod_security rule triggered!
[Fri Nov 18 15:00:17 2011] [error] [client 212.35.29.175] ModSecurity: Access denied with code 403, [Rule: 'ARGS' '(fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->)']
[Msg: XSS attack]

How can we fix that?

regards

Urs
 

NiteWave

Administrator
#2
for quick solution, just disable this rule:
admin console --> Server --> Request Filter -->XSS attack

does this happen on firefox only ?
 
Top