Jump to content

Version identifies security vulnerability


Guest Denver Dave

Recommended Posts

Guest Denver Dave

I know this has been discussed before, but think it is worth bringing up again. It is a bad security risk to identify the minor version number levels for Cubecart. Just noticed in our website statistics that we had a search for "powered by cubecart 3.0.3". The only reason that I can think of that someone would do this is to exploit the 3.0.3 vulnerability. We have now upgraded to 3.0.6 or at least testing.

Would be much better to just identify Cubecart 3, but not the version. phpBB adopted this scheme.

Link to comment
Share on other sites

Guest hennaboy

It is always going to be a problem showing any versions of anything.

PHP, MYSQL, APACHE and so on all show version numbers that are all then subject to attack when a security exploit is revealed.

I agree that perhaps we should have the option to show the version number and only display powered by cubecart.

Or purchase cc and dont display anything at all ;)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...