Results 1 to 7 of 7
  1. #1
    Join Date
    Dec 2007
    Location
    London
    Posts
    184
    Plugin Contributions
    0

    Default SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

    Had a quick search of the forums and was surprised I couldn't find too much detail relating to this.

    We've been battling the issue of PCI compliance on and off for about 2 years (as covered here). Ultimately we're still not compliant.

    I'm not sure how strongly enforced PCI compliance is in other territories but we're UK based and have been receiving monthly fines for non compliance for well over a year.
    Our bank is now doubling the monthly non-compliance fine.
    To try and resolve the problem we've migrated to a private server in recent weeks which has certainly helped but SecurityMetrics are still finding vulnerabilities within PHP scripts on the server, i.e. client side issues with Zen Cart.

    I'm aware that the next big release of Zen Cart is supposed to address PCI compliance, but does anyone have any experience of making their current Zen Cart store compliant or perhaps can recommend someone we can ask for help?

    We've reached the point where we're seriously considering switching to an entirely new ecommerce platform to achieve compliance.

  2. #2
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,761
    Plugin Contributions
    9

    Default Re: Achieving PCI compliance with Zen Cart 1.3.x

    Try completing the details as outlined in the posting FAQ's

    http://www.zen-cart.com/forum/faq.php

    Also what specific "vulnerabilities" are being referenced?
    Are these due to php version?
    If so, no script will be compliant
    Zen-Venom Get Bitten

  3. #3
    Join Date
    Dec 2007
    Location
    London
    Posts
    184
    Plugin Contributions
    0

    Default Re: Achieving PCI compliance with Zen Cart 1.3.x

    No they're not due to PHP version.

    Vulnerabilities highlighted are script issues.

    Vulnerabilities such as
    Script allows response splitting (Phorum)
    Script allows response splitting (Surveys)
    Script allows response splitting (W-Agora)
    Script allows response splitting (webcalendar)
    The remote web server contains a PHP script that is prone to an information disclosure attack.

    We're running 1.3.9h, PHP 5.2.17, MySQL 5.0.92-community, hosted on a virtual private server

  4. #4
    Join Date
    Feb 2005
    Location
    Lansing, Michigan USA
    Posts
    20,024
    Plugin Contributions
    3

    Default Re: Achieving PCI compliance with Zen Cart 1.3.x

    I'm no expert, but it looks to me that those issues have nothing to do with Zencart. Do you have those scripts installed ?

  5. #5
    Join Date
    Dec 2007
    Location
    London
    Posts
    184
    Plugin Contributions
    0

    Default Re: Achieving PCI compliance with Zen Cart 1.3.x

    Thanks for that, I think I know where to start looking.

    I'm not familiar with the scripts but it's most likely that some of the custom mods that we've had developed are the root of the problem.

  6. #6
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,761
    Plugin Contributions
    9

    Default Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on the serve

    Ditto stevesh

    Those processes are not ZenCart processes TMK
    Zen-Venom Get Bitten

  7. #7
    Join Date
    Feb 2010
    Posts
    28
    Plugin Contributions
    0

    Default Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

    W-Agora is web publishing and forum script,
    Phorum is PHP opensource. You are having compliance problems! None of those scripts are Zencarts

 

 

Similar Threads

  1. Any current vulnerabilities in sqlpatch.php ?
    By tj1 in forum General Questions
    Replies: 1
    Last Post: 7 Jul 2012, 04:28 AM
  2. SecurityMetrics PCI compliance fail: /password_forgotten.php
    By MickeyDora in forum General Questions
    Replies: 2
    Last Post: 18 May 2011, 07:10 AM
  3. php scripts?
    By SilverKop in forum General Questions
    Replies: 3
    Last Post: 28 Aug 2009, 10:48 AM
  4. New server finding the sql server name
    By snowy2007 in forum Installing on a Linux/Unix Server
    Replies: 2
    Last Post: 2 Oct 2008, 05:40 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR