osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

[Security Advisory] Information Leak/Vulnerability in osCMax

This is a discussion on [Security Advisory] Information Leak/Vulnerability in osCMax within the osCMax v1.7 Announcements forums, part of the osCMax v1.7 Forums category; Attention osCMax/BTS users: We have been notified of a vulnerability in the BTS system that will allow a user to ...



Find us on Facebook
Go Back   osCommerce and osCMax shopping cart software forums > osCMax v1.7 Forums > osCMax v1.7 Announcements

Connect with Facebook Register FAQDonate Members List Calendar Mark Forums Read


Closed Thread

 

LinkBack Thread Tools
  #1  
Old 03-20-2005, 01:32 PM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 15,683
Thanks: 139
Thanked 606 Times in 519 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default [Security Advisory] Information Leak/Vulnerability in osCMax

Attention osCMax/BTS users:

We have been notified of a vulnerability in the BTS system that will allow a user to view/execute arbitrary files on a server.
If you are using osCMax or BTS with standard osCommerce, this bug affects you. This bug is fairly severe, and should be corrected immediately.

The osCMax current v1.7 download file has been patched as of today.

The following files are affected:

main_page.tpl.php
popup.tpl.php


Because this problem is with the BTS template files, the best way to fix this is manually, as a patch file would most certainly break any customized template. The vulnerable code is found in all the different templates (aabox, osC, OneTable, etc) and you should patch the code in all template directories, if they remain on your server. It is also recommended that you remove any template directories that you are not using.

Thank you,

Michael Sasek
osCDox.com

If you do not have any of the vulnerable code in your templates, you are not affected by this bug.

Below you will find instructions on how to correct this issue. :

****** Begin Vulnerability Fix ********
--------------------------------------------------------
In main_page.tpl.php find:
Code:
<?php if ($javascript) { require(DIR_WS_JAVASCRIPT . $javascript); } ?>
Replace with:
Code:
<?php if (isset($javascript) && file_exists(DIR_WS_JAVASCRIPT . basename($javascript))) { require(DIR_WS_JAVASCRIPT . basename($javascript)); } ?>

---------------------------------------------------------

Find:
Code:
if (isset($content_template)) {
Replace with:
Code:
if (isset($content_template) && file_exists(DIR_WS_CONTENT . basename($content_template))) {
----------------------------------------------------------

Find:
Code:
require(DIR_WS_CONTENT . $content_template);
Replace with:
Code:
require(DIR_WS_CONTENT . basename($content_template));
----------------------------------------------------------
In popup.tpl.php find:

Code:
<?php if ($javascript) { require(DIR_WS_JAVASCRIPT . $javascript); } ?>
Replace with:
Code:
<?php if (isset($javascript) && file_exists(DIR_WS_JAVASCRIPT . basename($javascript))) { require(DIR_WS_JAVASCRIPT . basename($javascript)); } ?>
******* End Vulnerability Fix ********
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
osCMax 2.0RC2 Security Patch/Update 051112 wilde-uk osCMax v2 Installation issues 5 04-12-2006 08:45 PM
Security Patch osCMax 2.0RC2 warrenthewindmill osCMax v1.7 Discussion 2 12-04-2005 10:50 AM
osCMax 2.0RC2 Security Patch/Update 051112 michael_s Announcements 0 11-27-2005 10:12 AM
Information Box in RC2... [wicked] osCMax v2 Customization/Mods 0 10-21-2005 06:00 PM
Security Patches for osCMax v1.7?? jpepper osCMax v1.7 Discussion 2 08-12-2005 11:49 AM


All times are GMT -8. The time now is 01:02 PM.


Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO
Copyright 2009 osCMax
Inactive Reminders By Icora Web Design