I must say that, I forgot what and how I did it, but instead of a 404 page, a missing/wrong URL requests are being forwarded to the main page on my web site. Is that a problem?
They also posted a separate warning as follows. Note, I use JReviews for ratings and reviews:
Synopsis:
The remote web server is prone to cross-site scripting attacks.
Description:
The remote web server hosts cgi scripts that fail to adequately sanitize parameters name of
malicious JavaScript. By leveraging this issue, an attacker may be able to cause arbitrary HTML and script code to be executed in a user's browser within the security context of the affected site.
Output:
Using the GET HTTP method, Site Scanner found that :
+ The following resources may be vulnerable to XSS (on parameters names) :
/resorts/americas/resorts?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72
%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /resorts/americas/resorts?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<!--[if lte IE 6]><script type="text/javascript" src="https://www.akeeba.com/components/ [...]
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] s/americas/resorts? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
<link rel="stylesheet" type="text/css" href="http://mydomain.com [...]
------------------------
/resorts/americas/resorts/?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%7
2%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /resorts/americas/resorts/?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<!--[if lte IE 6]><script type="text/javascript" src="https://www.akeeba.com/components/ [...]
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] /americas/resorts/? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
<link rel="stylesheet" type="text/css" href="http://mydomain.com [...]
------------------------
/resorts/americas?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%
31%33%29%3C%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /resorts/americas?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<!--[if lte IE 6]><script type="text/javascript" src="https://www.akeeba.com/components/ [...]
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] m/resorts/americas? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
<link rel="stylesheet" type="text/css" href="http://mydomain.com [...]
------------------------
/resorts/americas/north-america/?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%
65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /resorts/americas/north-america/?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<!--[if lte IE 6]><script type="text/javascript" src="https://www.akeeba.com/components/ [...]
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] ricas/north-america/? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
<link rel="stylesheet" type="text/css" href="http://mydomain.com [...]
------------------------
/resorts/americas/north-america?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%6
5%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /resorts/americas/north-america?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<!--[if lte IE 6]><script type="text/javascript" src="https://www.akeeba.com/components/ [...]
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] ericas/north-america? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
<link rel="stylesheet" type="text/css" href="http://mydomain.com [...]
------------------------
/contact?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C
%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /contact?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] teaplace.com/contact? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
------------------------
/resorts/americas/?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33
%31%33%29%3C%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /resorts/americas/?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<!--[if lte IE 6]><script type="text/javascript" src="https://www.akeeba.com/components/ [...]
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] /resorts/americas/? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
<link rel="stylesheet" type="text/css" href="http://mydomain.com [...]
------------------------
/resorts/americas/north-america/usa?%FF%FE%3C%73%63%72%69%70%74%3E%61%
6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1
-------- request --------
GET /resorts/americas/north-america/usa?%FF%FE%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%33%31%33%29%3C%2F%73%63%72%69%70%74%3E=1 HTTP/1.1\r
Host: mydomain.com\r
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r
Accept-Language: en\r
Connection: Close\r
Cookie: 2f4b27f97f06a134af69ddcdc426c684=79a899be4ce16e3808d28e9efd156f7d\r
User-Agent: Mozilla/5.0 (compatible; MSIE 7.0; MSIE 6.0; Site Scanner Bot; +http://www.websiteprotection.com) Firefox/2.0.0.3\r
Pragma: no-cache\r
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
------------------------
-------- output --------
<meta property="og:description" content="Resorts reviews, rating, [...]
<script type="text/javascript" src="http://connect.facebook.net/en [...]
[...] as/north-america/usa? <script>alert(313)</script>=1';}});}}};function fa [...]
--></script>
------------------------
Other references : CWE:79, CWE:80, CWE:81, CWE:83, CWE:20, CWE:74, CWE:442, CWE:712, CWE:722, CWE:725, CWE:811, CWE:751, CWE:801, CWE:116