Security of osCommerce

From: Joel Merrick (joel_at_servicestyle.com)
Date: 01/18/05

  • Next message: Vladimir Kraljevic: "HKLM locking"
    To: vuln-dev@securityfocus.com
    Date: Tue, 18 Jan 2005 17:18:59 +0000
    
    
    

    Hi,

    I'm wondering if anyone can tell me about the current security status of
    the MS2.2 release of osCommerce?

    I understand that there have been XSS vulnerabilities and DOS exploits,
    heve these been fixed in the MS2.2 downloadable from the site?

    Any help appreciated, the forums deleted my post because it contained an
    URL to a Security foucussed osCommerce project (nothing getting sold
    though!). Open source? :)

    -- 
    Joel Merrick
    
    



  • Next message: Vladimir Kraljevic: "HKLM locking"

    Relevant Pages

    • [Full-Disclosure] Security status of osCommerce?
      ... I'm wondering if anyone can tell me about the current security status of ... the MS2.2 release of osCommerce? ... I understand that there have been XSS vulnerabilities and DOS exploits, ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: OS Commerce
      ... around for ages and I personally prefer someone else to take care of the security. ... The basic account is free. ... I was thinking of just using oscommerce and paypal to get me back up and running. ...
      (uk.people.consumers.ebay)
    • [Full-disclosure] RE:DONT SEND ME AGAIN PLS
      ... XSS vulnerabilities in Google.com ... XSS vulnerabilities in Google.com (GroundZero Security) ... [Full-disclosure] XSS vulnerabilities in Google.com ... It lists the folks that they might ...
      (Full-Disclosure)
    • Authenticaion bypass, Directory transversal and XSS vulnerabilities in PayProCart 3.0 - Profitcode S
      ... Dcrab 's Security Advisory ... There are, authenticaion bypass, directory transversal and xss vulnerabilities in payprocart 3.0 - profitcode software. ...
      (Bugtraq)
    • [UNIX] Outreach Project Tool Multiple Vulnerabiltiies
      ... Beyond Security would like to welcome Tiscali World Online ... Typical XSS vulnerabilities exist in many/most of the community-functions. ... If the lockfile "lock01" is found in the setup_lock-directory and it is ... Execute system-commands thru the setup.php - script. ...
      (Securiteam)