LockedSecurity Issues in Click and Install Applications

Author
plateaultd
Senior Member
2008/01/26 22:15:37 (permalink)

Security Issues in Click and Install Applications

Having to deal with the recent Security Issues in HC 6.1 led me to look into exactly what versions of "Click and Install" applications were available with HC 7, their pay for install open source software.

Before you make any of these available you might want to check the versions being installed on your server and see what the current release version is.

I have made it a point to disable all of these on the one server we have been able to upgrade to 7 so far as I would prefer to not allow our customers to be able to install software with security flaws that they get from us.

Version
SOftware Installed Current
---------------------------------------
bBlog 0.7.6 ???
comersus 7.0.2 7.095
Coppermine 1.4.10 1.4.14 - Security release (Nov 2007)- CSS issues!
Crafty Syntax 2.12.9 2.14.5 (Live Help SOftware)
Forum ??? ???
Gallery 2.1 2.1 2.2.4 This release fixes critical security issues.
Joomla 1.0.12 1.0.13 Multiple Security Issues Fixed in Release
Mambo 4.6.1 4.6.3 On 23 Jan 2008 Issued a security advisory and patch
myLittleAdmin ??? ??? myLittleTools.net
osCommerce 2.2 ??? November 2005 release - Latest version released Jan 2008
phpBB 2.0.18 2.0.22 (legacy Version - current version is 3.0 and was released 12/2007)
phpMyAdmin 2.9.1.1 2.11.4 There are multiple security advisories for versions prior to 2.11.2
PHPSupportTickets ??? 2.2 Appears to be latest version
plogger Beta 2 Beta 3
phpNuke 1.1 or 1.3? 8.1 Appears to be from 2005, version varies in file
Snitz Forums 3.4.05 3.4.06 Various security patches on website
WebCalendar 1.0 1.1.6 Various Security Fixes
Wordpress 2.0 2.0.11 They have security updates for legacy version, current Version 2.3.2
XOOPS 2.0.15 2.0.18 Various security fixes
Zencart 1.3.0.2 1.3.8 Various Security Fixes


Hosting Controller, are you planning on supporting this software and getting the latest versions installed on the server? If so, when???

#1

5 Replies Related Threads

    plateaultd
    Senior Member
    RE: Security Issues in Click and Install Applications 2008/01/27 11:06:35 (permalink)
    I apologize for taking up bandwidth here, but it appears like HC other security issues this one has been around for at least 9 months.

    http://forum.hostingcontroller.com/topic.asp?TOPIC_ID=4596


    #2
    HC Team
    Hosting Controller
    RE: Security Issues in Click and Install Applications 2008/01/28 04:28:04 (permalink)
    After the release of upcoming build you will be able to see click and install apps. versions in HC7 panel.

    These are not HC7 issues infact these are related to third partiese supported by hosting controller. As I already explained in this thread, we will upgrade click and install versions in each HC7 build.

    ________________________
    HC Support Team
    support@hostingcontroller.com
    http://hostingcontroller.com
    +1-213-341-1419
    #3
    plateaultd
    Senior Member
    RE: Security Issues in Click and Install Applications 2008/01/28 11:51:38 (permalink)
    Your including old version in HC makes it your problem!

    I have the latest version of HC 7, which I downloaded using the URL your support provided, within the last 10 days. Build 12 for Hosting Controller was released on 1 Jan 2008, which then tells me that you should have been up to date on many of these software packages. Almost all of the updates were released in Dec of 2007 and earlier, which means their updates should have been in the build, but they were not. I am sure that others will agree with me that this warrants a special service pack/hot fix ASAP, otherwise they are useless.

    Some of these issues have been around for over 9 month, which tells me that you have had more than enough time to include the latest packages.

    The internet is NOT as safe place, it's time you stop being part of the problem and become part of the solution.


    quote:
    Originally posted by HC Support
    [br]After the release of upcoming build you will be able to see click and install apps. versions in HC7 panel.

    These are not HC7 issues infact these are related to third partiese supported by hosting controller. As I already explained in this thread, we will upgrade click and install versions in each HC7 build.

    ________________________
    HC Support Team
    support@hostingcontroller.com
    http://hostingcontroller.com
    +1-213-341-1419



    #4
    plateaultd
    Senior Member
    RE: Security Issues in Click and Install Applications 2008/02/21 08:27:10 (permalink)
    In checking the release notes for build 13 I don not see where you have upgraded all the Click and Install apps to the latest respective version.

    So two questions:
    1. Has this been done?
    2. If so can you amend your release notes to state what was upgraded and the version upgraded to?

    This will make it so much easier to keep track of this.
    Thanks

    #5
    HC Team
    Hosting Controller
    RE: Security Issues in Click and Install Applications 2008/02/22 03:37:31 (permalink)
    You can check click and install apps. version at this path Server Manager--->Global Settings of HC panel. We will try to upgrade click and install apps. periodically.

    ________________________
    HC Support Team
    support@hostingcontroller.com
    http://hostingcontroller.com
    +1-213-341-1419
    #6
    Jump to: