Zen Cart Security Vulnerability Alert

Zen Cart Security Vulnerability Alert - Computer Issues, Video Gaming - Posted: 28th Jun, 2009 - 10:55pm

Text RPG Play Text RPG ?
 

Posts: 1 - Views: 1317
28th Jun, 2009 - 10:55pm / Post ID: #

Zen Cart Security Vulnerability Alert

Zen Cart Security Vulnerability Alert

Those of you using Zen Cart may want to act quick. I got this Zen Cart Security Vulnerability Alert in my Email:

QUOTE
Zen Cart Security Vulnerability Alert + Patch

Please pardon this mass email. If you are running a Zen Cart store, it's important that you read this message and take action immediately.


A vulnerability has been discovered in the admin section of v1.3.8 (and previous versions). To take advantage of this vulnerability any attacker must know the URL of your admin section. As our security recommendations point out, you should change the folder that your admin resides in as soon as you  installed Zen Cart.

SO -- THE FIRST STEP YOU **NEED** TO TAKE is to rename your /admin/ folder!
Source 3


However we realise that relying on this 'Security through Obscurity' is not foolproof, hence the release of a patch, which can be downloaded from the Zen Cart Support forum, here: Source 6

The zip file there contains a readme.html with full details on how to install the security patch files. The security patch uses Zen Cart's override system to make installation as simple as possible.

The security patch will work for previous versions in the 1.3.x series.

Older releases I.e v1.2.x are no longer supported and the patch has not  been fully tested on those versions, however some parts of the patch should still work with v1.2.x (again see the readme.html file). However we strongly advise anyone using the 1.2.x versions to upgrade to 1.3.8 as soon as possible.

The Zen Cart Team takes security matters very seriously. But security is only as good as those who follow posted recommendations. Please apply the appropriate patches and security measures promptly, for your own benefit.


SUMMARY:  Your Action Steps are:

1. RENAME YOUR ADMIN FOLDER ! 
Yes, if you haven't already renamed your /admin/ folder, do it NOW!
Instructions can be found here: Source 5

2. APPLY THE SECURITY PATCH !
Source 2

3. Subscribe yourself to the Zen Cart Announcements mailing list:
Source 3

4. Keep your site's Zen Cart software up-to-date at all times. Numerous bugs, improvements, and security fixes are included in every new release. It is in your best interests to remain current.
Source 4


Sincerely,
The Zen Cart Team




Sponsored Links:
Post Date: Sun Feb 23 15:25:17 GMT 2025 / Post ID: #

Avatar

Zen Cart Security Vulnerability Alert

Add Comment
In my opinion zen cart security vulnerability alert it should be investigated soon so there can be carefully and seperate fact from fiction.


 
> TOPIC: Zen Cart Security Vulnerability Alert
 

▲ TOP


International Discussions Coded by: BGID®
ALL RIGHTS RESERVED Copyright © 1999-2025
Disclaimer Privacy Report Errors Credits
This site uses Cookies to dispense or record information with regards to your visit. By continuing to use this site you agree to the terms outlined in our Cookies used here: Privacy / Disclaimer,