Post by worldpeace » Thu Aug 20, 2009 6:24 am

Hi there,

I just found out about OpenCart ecommerse script and heard mixed reviews about security issues. How many of you guys out there run a pretty large site with OC and haven't had any security issues?

Newbie

Posts

Joined
Thu Aug 20, 2009 6:19 am

Post by Daniel » Thu Aug 20, 2009 9:58 am

there was one problem with version 1.18. It was not a major security problem.

thats it out of all the releases!

there is no security problems with opencart!

its probabl;y the most secure cart out there!

where are these reviews?


it seems that the same security issue is spread among thousands of sites.

I was actually told about the problem by the person that that put the alert out 1 month before he made the problem know to the security sites.

OpenCart®
Project Owner & Developer.


User avatar
Administrator

Posts

Joined
Fri Nov 03, 2006 6:57 pm

Post by Daniel » Thu Aug 20, 2009 10:06 am

Just looking at some security web sites that there are 100's of security problems that have been reported with oscommerce, cubecart, zen cart, magento prestashop.

Heres a nasty one for Prestashop:
http://xforce.iss.net/xforce/xfdb/47158

Magento:
http://www.molotovbliss.com/blog/magent ... erability/

osCommerce:
http://www.securiteam.com/unixfocus/6O00C1P95E.html

ZenCart
http://www.securityfocus.com/bid/15690/exploit

OpenCart®
Project Owner & Developer.


User avatar
Administrator

Posts

Joined
Fri Nov 03, 2006 6:57 pm

Post by twiggy » Fri Aug 21, 2009 5:27 am

Daniel we know the others are buggy and have lots of holes so don't think 'slagging' them off is appropriate.

Think its more important to concentrate on opencart and not the others ^-^

I have done a search the only problems I can find all look towards version 1.1.8 which that hole has now been fixed.

What about this one? http://www.juniper.net/security/auto/vu ... 34724.html thats the only link I can find that's slightly different report to the others.

Active Member

Posts

Joined
Fri Aug 14, 2009 4:43 am


Post by Daniel » Fri Aug 21, 2009 5:57 am

that was fixed the same time.

OpenCart®
Project Owner & Developer.


User avatar
Administrator

Posts

Joined
Fri Nov 03, 2006 6:57 pm

Post by twiggy » Fri Aug 21, 2009 6:30 am

well think its all safe as can be for now ;D

Active Member

Posts

Joined
Fri Aug 14, 2009 4:43 am


Post by maxila » Mon Aug 16, 2010 9:47 pm

hi

is there any important security issue in opencart 1.2.8 ? I have a shop with this version for some reason I can not upgrade it. please let me know if there is any important problem in 1.2.8

thanks

Newbie

Posts

Joined
Mon Aug 16, 2010 9:40 pm

Post by i2Paq » Tue Aug 17, 2010 1:41 am

Upgrading from versions previous to 1.2.9 is not possible.

If you run a store on version 1.2.9 you first need to upgrade to 1.3.0 and then to 1.3.2. To do this follow the instructions found in the various chapters on this page.

OpenCart 1.4.7 and later comes with an upgrade script. Follow these instructions for Upgrading to 1.4.7 or later. The upgrade script can be used to upgrade your site from as far back as 1.3.2.
Please read

Norman in 't Veldt
Moderator OpenCart Forums

_________________ READ and Search BEFORE POSTING _________________

Our FREE search: Find your answer FAST!.

[How to] BTW + Verzend + betaal setup.


User avatar
Global Moderator

Posts

Joined
Mon Nov 09, 2009 7:00 pm
Location - Winkel - The Netherlands

Post by maxila » Tue Aug 17, 2010 4:09 am

I do not want to upgrade. I just want to know if there is any security bug and how to fix it.

Newbie

Posts

Joined
Mon Aug 16, 2010 9:40 pm

Post by Xsecrets » Tue Aug 17, 2010 4:17 am

yes there is a CSRF posibility, and it's not an easy fix the token system was added to several places in every single admin file, so you'll either have to upgrade or live with the security vulnerability.

OpenCart commercial mods and development http://spotonsolutions.net
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter


Guru Member

Posts

Joined
Sun Oct 25, 2009 3:51 am
Location - FL US

Post by Qphoria » Tue Aug 17, 2010 4:57 am

Xsecrets wrote:yes there is a CSRF posibility, and it's not an easy fix the token system was added to several places in every single admin file, so you'll either have to upgrade or live with the security vulnerability.
Tho the url class existed there so it would be a lot less work. But still better to upgrade

Image


User avatar
Administrator

Posts

Joined
Tue Jul 22, 2008 3:02 am

Post by maxila » Tue Aug 17, 2010 5:33 pm

I am familiar with php, if you tell me where is the problem I could be able to fix it myself. if you wish please PM me detail. thanks.

Newbie

Posts

Joined
Mon Aug 16, 2010 9:40 pm

Post by Xsecrets » Tue Aug 17, 2010 8:30 pm

maxila wrote:I am familiar with php, if you tell me where is the problem I could be able to fix it myself. if you wish please PM me detail. thanks.
If you'll just search the forums. for CSRF you will find it.

OpenCart commercial mods and development http://spotonsolutions.net
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter


Guru Member

Posts

Joined
Sun Oct 25, 2009 3:51 am
Location - FL US

Post by Qphoria » Tue Aug 17, 2010 9:22 pm

actually if you get the old "extension.zip" pack from here:
http://code.google.com/p/opencart/downloads/list

There is a file called CSRF or oc_csrf.zip in there. That has the steps needed to add a token system using the url class. It was for 1.4.0 I believe, but if you know php you might be able to figure out how to add it to 1.2.9

Image


User avatar
Administrator

Posts

Joined
Tue Jul 22, 2008 3:02 am

Post by maxila » Wed Aug 18, 2010 3:29 am

thank you very much for your helps Qphoria and xsecrets :)

Newbie

Posts

Joined
Mon Aug 16, 2010 9:40 pm
Who is online

Users browsing this forum: No registered users and 24 guests