Critical Zen Cart Vulnerability Could Spell Black Friday Disaster For Shoppers (htbridge.com)
Mark Wilson writes: It's around this time of year, with Black Friday looming and Christmas just around the corner, that online sales boom. Today security firm High-Tech Bridge has issued a warning to retailers and shoppers about a critical vulnerability in the popular Zen Cart shopping management system. High-Tech Bridge has provided Zen Cart with full details of the security flaw which could allow remote attackers to infiltrate web servers and gain access to customer data. Servers running Zen Cart are also at risk of malware, meaning that hundreds of thousands of ecommerce sites pose a potential danger. Technical details of the vulnerability are not yet being made public, but having notified Zen Cart of the issue High-Tech Bridge says the date of full public disclosure is 16 December.
All I keep seeing day in and day out are how buggy the crap you webchumps make is and the frameworks you use too. Nearly every single day the news shows it.
High-Tech assholes want to make a name for themselves. I bet they've been sitting on this just waiting for this time of year.
First?!?! FIRST POST
say something. don't ask, don't tell. bacon is bad. now what was that again?
Hack Friday ... amirite?
-- Brought to you by Carl's JR
More shit php/MySQL.
php & MySQL so easy to use any dumb-fucker can use them without reading the manual.
Do you really want a dumb fucker who doesn't read the manual writing your e-commerce site?
I don't know about zen cart, but it's based on osCommerce which is a nasty piece of shit.
According to the original source (https://www.htbridge.com/advisory/HTB23282) the security issue affects versions 1.5.3 "and probably prior" (you gotta love the wording). When I looked at the Zen Cart site today v1.5.4 has been out for almost a year. Now someone else please take it from here...
We don't need to escape strings, because back in 2005 we wrote a regex that checks for SQL injection attacks. It worked with all five examples we threw at it, which is basically test driven development.
D-I-S-A-S-T-E-R
Roast Turkey, of course.
Cryonics - Keep cool and carry on.
Zencart? How is a typical shopper supposed to know if the online retailer that they are using is using the Zencart system?
Critical Zen Cart Vulnerability Could Spell Black Friday Disaster For Shoppers. This a great online sales boom. I really enjoy this post.
The Zen Cart code is a mess, and I'm not surprised that it has vulnerabilities.
XCart seems much better, but it's a monster codebase. It probably has some vulnerabilities too.
Just cruising through this digital world at 33 1/3 rpm...
I am sure they just happened to discover the flaw at this time. It's not like they where sitting on the discovery, releasing the warning at maximum point of hysteria..
Could somebody post the original article that this post summarizes? e.g. Where can we get further information?
Because of this, or in spite of this, or regardless of this (choose one), I will not be doing any black Friday shopping. I choose not to commemorate the anniversary of the collapse of gold prices in the stock market.
If you are not allowed to question your government then the government has answered your question.
you both said "webchumps", are you have a bout of schizophrenia again?
I want to own some retards running php
No panic... a patch is out already.
/ajax.php file has a vulnerability which can be used to cause a server exploit under very specific conditions.
/ajax.php file with the one attached below.
In Zen Cart v1.5.4 the
The patch is simple: replace the
https://www.zen-cart.com/showt...