Get Expert Website Hosting

Choose website reliability and expertise with SiteGround!

Security Service Updates

osCommerce Vulnerability Fixed on All SiteGround Servers

Jan 08, 2010 1 min read Hristo Pandjarov

As probably most of you know, osCommerce is a shopping cart application for creating and managing online stores. It is very widely used and has many implementations and variations. Many popular shopping cart applications like OscMax, ZenCart, CreLoaded, etc. are actually based on osCommerce and use its code.

Unfortunately, for quite a while now, there has been a known vulnerability in the osCommerce code and the code of the applications based on it through which a hacker can exploit the admin area and take malicious actions. Although on the osCommerce official website there is some information how the problem can be avoided (http://svn.oscommerce.com/jira/browse/OSC-1069), the vulnerability has not been fixed yet in the latest osCommerce release and with each new download and installation of a related shopping cart software, new people and online stores become potential targets.

When there is a vulnerability in such a popular application and many sites are at risk, we at SiteGround do not believe in the approach: “let each user find and apply the bug fix him/herself”. First, most of the users understand about the issue only after they are already affected. Second, many of them are unable to apply the fix themselves. To protect our customers from hacker attacks, some of our best technical experts investigated the problem in details and applied a global solution to all potentially vulnerable customers’ applications.

The results from our osCommerce patch operation are:

  • the osCommerce package available for installation through Fantastico has been patched so that the new installations are not vulnerable to the exploit;
  • all future transfer clients with osCommerce-based websites will get the vulnerability fix as part of the website transfer service we provide;

We are proud that once again SiteGround has provided a security service high above the standard level for a shared hosting company. Our knowledge and reaction in situations like these make us believe that we do provide the best osCommerce hosting.

Hristo
Product Development – Technical

Share this article

Hristo Pandjarov

Product Innovation Director

Enthusiastic about all Open Source applications you can think of, but mostly about WordPress. Add a pinch of love for web design, new technologies, search engine optimisation and you are pretty much there!

More by Hristo

Related Posts

Gemini AI: Now Included in All Google Workspace Plans Offered by SiteGround

Last year, we proudly announced our partnership with Google Workspace, bringing the ultimate collaboration and productivity…

  • Feb 14, 2025
  • 2 min read

The Complete WordPress Security Guide + the Best Fixes

WordPress powers over a whopping 40% of the web. That’s an awful lot of websites—and also…

  • Feb 12, 2025
  • 9 min read

PHP 8.4 Highlights: What is New, Features and Improvements Explained

Packed with powerful features and enhancements, the latest PHP 8.4 version promises to make coding more…

  • Jan 30, 2025
  • 8 min read

Comments ( 4 )

author avatar

Zinc Supplement

Aug 08, 2011

interesting. wonder what they use for blocking? seems to work well.

Reply
author avatar

Kanwal

Jan 20, 2013

Very nice collection of free matnego themes. I bookmarked this page! I tried to install matnego on my hosting server, but I have old version of PHP. I tested matnego just with the demo site on the official website, and I think it's the perfect ecommerce script! Regards!

Reply
author avatar

Zoplay

Mar 31, 2015

Hello, i would like to report a 0day vulnerability that works on the latest version of oscommerce 2.3.3.4 i don't want to disclose more information here on public before applying a fix can you advice where i can send the security report ? i cannot find a free way to contact the support

Reply
author avatar

Hristo Siteground Team

Apr 01, 2015

Hey, you can shoot us an email at responsible-disclosure@siteground.com :)

Reply

Leave a comment

Add comment