It appears you have not yet registered with our community. To register, please click here...

AWH Forums  

Go Back   AWH Forums > AWH > Announcements > Virus & Scam Alerts

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 12-23-2009, 10:24 AM
Ronnie Ronnie is offline
#1 Administrator
 
Join Date: Apr 2002
Location: Dallas, TX
Posts: 1,732
OSCommerce vulnerabilities

The latest version of OSCommerce as of the date of this post is:

osCommerce Online Merchant v2.2 Release Candidate 2a

If you are not running this version or have not applied all patches, your system is not secure.


It has come to our attention that all versions of osCommerce appear to be vulnerable to exploitation if certain steps are not taken by site owners.

Details of the exploit(s) and steps you can take to protect your osCommerce installation can be viewed in the below osCommerce Forums posts:

http://forums.oscommerce.com/index.php?showtopic=313323
http://forums.oscommerce.com/index.php?showtopic=344651

This exploit allows the attacker to gain full access to your package and all data within, as well as use it for other potential malicious purposes such as sending spam mailings. Active exploits are taking place.

We are scanning the servers for osCommerce installations and we will be notifying site owners, on a domain by domain basis, of this information via email.

For those with an osCommerce installation requiring assistance with modifying their scripts we recommend visiting the osCommerce Forums:

http://forums.oscommerce.com/

Also note that all sites with third party scripts installed should take proactive steps to ensure they maintain all patches and upgrades for the scripts installed within an account and monitoring security forums or subscribing to security mailing lists for all installed scripts is strongly recommended.
__________________
Always Yours,

Ronnie T. Moore, Owner
AlwaysWebHosting.com • Friendly hosting & support
cPanel 11 with Fantastico • Host up to 10 domains!
We accept credit card & PayPal • 30-day guarantee
Visit us at http://www.alwayswebhosting.com/
Reply With Quote
 

Tags
oscommerce hack exploit

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Learning osCommerce akirk General 3 10-09-2007 05:36 PM


All times are GMT -6. The time now is 09:55 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.