<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Gravity Support Forums Topic: PCI Vulnerability Scanners Auto-Filling / Submitting Forms</title>
		<link>https://legacy.forums.gravityhelp.com/topic/pci-vulnerability-scanners-auto-filling-submitting-forms</link>
		<description>Gravity Support Forums Topic: PCI Vulnerability Scanners Auto-Filling / Submitting Forms</description>
		<language>en-US</language>
		<pubDate>Mon, 20 Apr 2026 13:40:53 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.1</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>https://legacy.forums.gravityhelp.com/search.php</link>
		</textInput>
		<atom:link href="https://legacy.forums.gravityhelp.com/rss/topic/pci-vulnerability-scanners-auto-filling-submitting-forms" rel="self" type="application/rss+xml" />

		<item>
			<title>Alex Cancado on "PCI Vulnerability Scanners Auto-Filling / Submitting Forms"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/pci-vulnerability-scanners-auto-filling-submitting-forms#post-146613</link>
			<pubDate>Wed, 13 Feb 2013 13:14:33 +0000</pubDate>
			<dc:creator>Alex Cancado</dc:creator>
			<guid isPermaLink="false">146613@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;I am tracking down this issue.&#60;/p&#62;
&#60;p&#62;Any chance you could take a look at your web server logs and find that exact request (form submission) made by the PCI vulnerability scanner. I need to replicate this issue locally and getting a hands on that request would be very helpful.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Hajer on "PCI Vulnerability Scanners Auto-Filling / Submitting Forms"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/pci-vulnerability-scanners-auto-filling-submitting-forms#post-146532</link>
			<pubDate>Wed, 13 Feb 2013 08:28:22 +0000</pubDate>
			<dc:creator>Chris Hajer</dc:creator>
			<guid isPermaLink="false">146532@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;I'll ask the development team about this one.&#60;/p&#62;
&#60;p&#62;For reference, related:&#60;br /&#62;
&#60;a href=&#34;http://www.gravityhelp.com/forums/topic/form-fields-are-populated-with-0s-zero&#34; rel=&#34;nofollow&#34;&#62;http://www.gravityhelp.com/forums/topic/form-fields-are-populated-with-0s-zero&#60;/a&#62;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>TSCADFX on "PCI Vulnerability Scanners Auto-Filling / Submitting Forms"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/pci-vulnerability-scanners-auto-filling-submitting-forms#post-146159</link>
			<pubDate>Tue, 12 Feb 2013 03:10:00 +0000</pubDate>
			<dc:creator>TSCADFX</dc:creator>
			<guid isPermaLink="false">146159@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;This has been discussed a couple times throughout the forum and there's never been a clear answer.  &#60;/p&#62;
&#60;p&#62;Some PCI vulnerability scanners can populate and submit forms even when phone number and email fields exist that error out on web-based submissions.  Somehow these scanners, which scan for vulnerabilities in many things such as web based forms, are able to submit these forms without triggering the errors.  This essentially confirms that there's a vulnerability because the form is able to be submitted without meeting the necessary requirements.  &#60;/p&#62;
&#60;p&#62;As many have mentioned the forms are typically submitted on average of 8 times per day, per form, and are filled with 0's.  The IP addresses do confirm that the forms are being filled by the scanners.  This appears to happen on both encrypted and non-encrypted pages as well as on stock WP and custom themed / with addons.  &#60;/p&#62;
&#60;p&#62;Installation Status&#60;br /&#62;
PHP Version 	5.3.3&#60;br /&#62;
MySQL Version 	5.1.67&#60;br /&#62;
WordPress Version 	3.5.1&#60;br /&#62;
Gravity Forms Version 	1.6.12
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
