osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 


Find us on Facebook
Go Back   osCommerce and osCMax shopping cart software forums > Blogs > michael_s's blog

Connect with Facebook Register FAQ Members List Calendar Mark Forums Read

* indicates required field

Navigation

User login

osCMax BugTracker

Who's online
There are currently 0 users and 31 guests online.

Syndicate
Syndicate content

 

Security Notice : osCMax 2.0.4 Released

By michael_s at 9 Nov 2009 - 7:02pm
michael_s's picture
A serious security vulnerability has been discovered in osCMax v2.0.3 and all prior versions. It is important that you follow the below instructions carefully to secure your site. Failure to do so could result in your site being breached by attack.

The following files must be removed from your site's administrative panel folder:

/admin/file_manager.php
/admin/define_language.php

Removing these files will close this vulnerability.

osCMax v2.0.4 has been posted to osCMax.com and the vulnerability has been patched. The security fix has also been added in SVN. It is recommended that all osCMax site owners remove these files immediately.

by user123 on Mon, 11/09/2009 - 8:38pm
Hi Michael,

Do we just need to remove those 2 files or do we have to install 2.04 as well? In the upgrade folder, I see 2 files - upgrade.php and sql file. Do we use this to upgrade from 2.03 to 2.04? It would be great if you can tell us how to update the site for newbies like me.

Thanks for the update.

Jay

by michael_s on Mon, 11/09/2009 - 8:51pm
michael_s's picture
Just delete the two files from your admin panel. That is all you need to do. No downloads needed.

by user123 on Mon, 11/09/2009 - 8:55pm
Cool! That's easy

by vallys on Tue, 11/10/2009 - 1:06am
Thanks for useful info!

by pgmarshall on Tue, 11/10/2009 - 2:12am
pgmarshall's picture
Michael,

Is this a temporary fix? Ie. Are we looking at replacing the file manager?

Define Languages - I never use anyway - but I do use the File Manager quite a lot! Especially when helping other people with their sites ... saves having to ask for FTP details which they never have ...

Since the File Manager is stand alone could we not rename it to a complete random name? Which coupled with the rename of the Admin folder make it reasonably secure again?

Do you have any more details of the security hole?

Regards,


All times are GMT -8. The time now is 07:29 PM.


Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO
Copyright 2010 osCmax
Inactive Reminders By Icora Web Design