Saturday, December 3. 2005
Zen-Cart <= 1.2.6d Security Fix
Trackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
Update: The Zen Cart team has released a patch to address this problem less than 12 hours after I posted a notice to their message board:
http://www.zen-cart.com/modules/ipb/index.php?act=ST&f=6&t=36760
I can only imagine that if the person who released this exploit information had gone to the Zen Cart team first, they would have been equally responsive, and the alert could have gone out along with the patch to fix it, saving everyone trouble.
http://www.zen-cart.com/modules/ipb/index.php?act=ST&f=6&t=36760
I can only imagine that if the person who released this exploit information had gone to the Zen Cart team first, they would have been equally responsive, and the alert could have gone out along with the patch to fix it, saving everyone trouble.
I agree that exposing problems before solutions exist is unethical. For the most part, I think professionals in the security community frown upon this.
However, there are those who are delighted to possess underground knowledge and who want to receive praise for every discovery made. If vulnerability discoveries are handled professionally, the researcher receives less attention.
Luckily, very few security professionals focus on attention and instead focus on improving security for everyone.
However, there are those who are delighted to possess underground knowledge and who want to receive praise for every discovery made. If vulnerability discoveries are handled professionally, the researcher receives less attention.
Luckily, very few security professionals focus on attention and instead focus on improving security for everyone.

