I found this web site that questions the vulnerability and security of Zen Cart.
Thought it was interesting and I would pass it on.. Maybe it's something we can work on fixing.![]()
http://www.osvdb.org/searchdb.php?vu...&search=search
I found this web site that questions the vulnerability and security of Zen Cart.
Thought it was interesting and I would pass it on.. Maybe it's something we can work on fixing.![]()
http://www.osvdb.org/searchdb.php?vu...&search=search
As far as I can see all those reports are about 1.3.0.2 or older versions. So I assume/hope upgrading to 1.3.6 should fix these problems.
What does "Status Stable" mean ?
PaulM is correct. The reported issues are all resolved and build-in to v1.3.5. Additional issues discovered by the Zen Cart team are included in v1.3.6.
It is recommended to upgrade to v1.3.6 to enjoy the security benefits, as well as the many other features and improvements contained therein.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
"Status Stable" just means they've stopped mucking with the details of their report and are satisfied that they can stop flogging it to say how bad it is or isn't. Basically it's an indicator to hackers about whether it's worth going after or whether they should wait until the vulnerability is deemed "stable" in order to go for the bigger payload.
Not exactly useful to anyone outside the "security vulnerability" industry.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Thanks, Dr. :-)
Sorry guys, i have to "VENT" on this one.....
its crap like that we dont need. Im sure that anyone of the zenners here that actualy make a living with this system are sad to hear that not only are there hackers out there waiting for the "prime time" to attack someone/company, but there is a place that shows them WHEN this time is good, and also go into details about the issue itself to point you directly to the place needed to "hack" the confidential data.
I already deal with fraudulant CC orders on a monthly basis!.(This is normal for my industry, and internet sales in general) I dont need the extra headache of wondering if someone is waiting to come take personal customer data which we hold so tight. Its horrable that is how our world works today...
Sure that site has its plus for the fact that it shows you this information, (im hoping for the benifit of being able to secure it down) but personaly i think its rediculas... Its like showing the world how the OK city bombing was created/exicuted in specific detail..... GRRRRRRRR!!!! Why not just ask someone to do it again?!?!?!?
Really the creators of this wonderfull system already know about issues and are always working hard to make sure they are rectified as quick as possable... So them -themselves dont really need this site to tell them where problems are... (this is why you donate to the team)....
Again, i dont mean to offend anyone with this post, im just in shock that we have sites like this around.... its just asking for trouble IMO......
Super Orders2
Info at a glance
export email address
encrypted master pass
quick updates
recover carts
order Tracking
Tabbed products lite - admin edition
Hosted with sashbox.net <- best host around...
I agree with you about being outraged with malicious hackers..
But the fact that that web site listed vulnerabilities is not nessasaraly a bad thing.. It helps with knowing the problem.. if you don't know what the problem is how do you know what needs to be fixed?
I guess rather than post the issue and directions on exactly HOW to use the security exploit, it would be much better for these "security reporters" to QUIETLY let the developers of what ever software know.
that way it can be fixed before the script kiddies read about HOW to break in
Zen cart PCI compliant Hosting
GARRANTEED,
none of the creators of zencart need any site to inform them on what is wrong with the software... If they dont happen to find it themself, then rest assured- someone in the forums will bring it up....
i believe the Merlin is right... it should be a more private thing....
Super Orders2
Info at a glance
export email address
encrypted master pass
quick updates
recover carts
order Tracking
Tabbed products lite - admin edition
Hosted with sashbox.net <- best host around...