Archive for the 'X-Cart Security Bulletins' Category

Increased Security in X-Cart Gold 4.1.11

With the release of 4.1.11, X-Cart Gold have put in an excellent, automated security measure with regards to the install.php.
To ensure the security of your X-Cart installation, the file install.php gets renamed to a random string of numbers and letters. This string is automatically created for you and is unique to your licence, just like [...]

Read More..>>

Security bulletin 20080806

Several moderate security issues have been identified in X-Cart. The issues make X-Cart-based stores potentially vulnerable to attackers who wish to make the application inoperable or gain access to the application back-end.
Qualiteam has released the security update which includes the following improvements.
All versions:
- the way adding/updating users worked, which was introduced in the previous patch, [...]

Read More..>>

Security bulletin 20080805

Several hack attempts on LiteCommerce stores were revealed recently.

Read More..>>

Security Bulletin - 20080703

During internal audit activities X-Cart have identified several moderate security vulnerabilities.
DESCRIPTION and IMPACT
In all X-Cart versions:
1. A malicious provider may ask the store administrator to use special symbols during creation of a provider account. In this case the provider can get access to the store files from the Files directory (or even outside of it).
2. [...]

Read More..>>