Results 1 to 3 of 3
  1. #1
    Join Date
    Jan 2010
    Location
    San Diego
    Posts
    30
    Plugin Contributions
    0

    Default SecurityMetrics PCI compliance fail: /password_forgotten.php

    I am failing the PCI compliance test from SecurityMetrics and they site this vulnerability:

    The remote web server contains a PHP application that is susceptible to an authentication bypass. Description : The version of Zen Cart installed on the remote host is affected by a design error that allows a remote attacker to bypass authentication and gain access to the application's admin section by appending '/password_forgotten.php' to URLs. Successful exploitation of this vulnerability may lead to disclosure of sensitive information such as customer data, SQL injection attacks, or arbitrary code execution.

    I have upgraded to 1.3.9h, deleted /docs, /extras, /zc_install, install.txt and renamed my admin folder immediately after installation.

    Does this sound like a problem with my host (BlueHost) or something else? Much appreciated.

  2. #2
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: PCI compliance fail: /password_forgotten.php

    Tell them their test is wrong. The mere existence of the password_forgotten.php file does not denote a vulnerability.
    That was an old vulnerability for a now-obsolete version.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: PCI compliance fail: /password_forgotten.php

    I would agree as well that SecurityMetrics needs to update their testing.

    Although it was true in the past, that appending '/password_forgotten.php' to certain URLs was indeed a potential vulnerability, the release of a patch for v1.3.8a and complete removal of that vulnerability within any v1.3.9 version makes it a moot point. Mind you, I still see those kinds of attempts which shows people are still trying it.
    Just another reason though, why using the current version -- as the OP already is --- is just a good thing to do.

 

 

Similar Threads

  1. v150 SecurityMetrics PCI scan keeps failing... NEED HELP!
    By bosrob in forum General Questions
    Replies: 2
    Last Post: 1 Feb 2012, 02:41 AM
  2. MSQL and PHP update - PCI Compliance
    By wapnoj in forum General Questions
    Replies: 0
    Last Post: 3 Aug 2010, 03:06 AM
  3. PCI COMPLIANCE: extras/curltest.php
    By Sir Paolo in forum General Questions
    Replies: 3
    Last Post: 21 Feb 2010, 08:38 PM
  4. Can I delete phpinfo.php for PCI Compliance
    By ecotopia in forum General Questions
    Replies: 3
    Last Post: 8 Oct 2009, 06:28 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg