Zen Cart Logo
Forums / Zen Cart Release Announcements / Admin Security -- Patch issued

Admin Security -- Patch issued

Locked

Views: 27,546

Results 1 to 1 of 1
This thread is locked. New replies are disabled.
1 Jul 2007, 9:57 PM
#1
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
177

Admin Security -- Patch issued

In Zen Cart v1.2 through v1.3.7 an admin vulnerability exists which could let a rogue user login to your admin area unmonitored.

As always, it is WISE TO RENAME YOUR ADMIN FOLDER.
If you have already renamed and not told anyone the new name of your admin folder, you are much less likely to be affected.

The patch should be applied based on the version you're using. You can find the patches at SourceForge:


v1.3.7
v1.3.6
v1.3.5
v1.3.0.2
v1.3.0.1
v1.3.0
v1.2.7
v1.2.6
v1.2.5 and earlier -- please upgrade to benefit from all other security fixes in newer versions.

REMEMBER -- The BEST SECURITY for your Admin area is to RENAME it from /admin/ to something else.
See your /docs folder for instructions, or see the FAQ here:
Security Recommendations, including Renaming the Admin folder

The Zen Cart team is thankful to Tomaz Bratusa at Team Intell for reporting this vulnerability.
Vulnerability issues should be reported to team AT zen-cart DOT com.