TulipTools Internet Business Owners and Online Sellers Community

Full Version: Zen Cart <= 1.2.6d (password_forgotten.php) SQL Injection Exploit
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
A new security hole was discovered a few hours ago in ZenCart ver 1.26d (the latest release).  No patch available at this time.  The affected file is admin/password_forgotten.php.  If you are using Zen it is highly advisable to temporarily disable the password_forgotten file (change its name to something like password_forgotten.phpmandy  Smile ).

In an SQL Injection attack the hacker is able to execute remote code on your MYSQL database and server-i.e. a hacker could run code to get all of your store's customer info and credit card numbers on your server, your passwords, etc. (a malicious hacker could even use the exploit to delete your entire database)

More info on this hole: http://www.addict3d.org/index.php?page=viewarticle&type=security&ID=5449

more info on SQL Injection here:
http://www.securiteam.com/securityreview...1P76E.html
http://www.unixwiz.net/techtips/sql-injection.html
NADA on the Zen support forums about the hole but I'm sure every hacker is already on Google looking for sites using Zen.   :blinkie: [url=http://directory.allmusicsearch.com/allmusicmeta/search/"zencart"-and-"sql-injection"/1-1.html]A search shows [/url] version 1.12d also had an SQL Injection problem and needed a patch.

Quote:NADA on the Zen support forums about the hole


Nope.

A useful resource to check to see if your scripts have any known security problems:

http://nvd.nist.gov/nvd.cfm
A patch to fix the hole is now available:

info: http://www.zen-cart.com/modules/mydownlo...php?cid=31
download: http://www.zen-cart.com/modules/mydownlo...hp?lid=544

All Zen Cart versions 1.1.x and 1.2.x require this patch not just 1.26d
That was quick.  Smile