Page 1 of 1

CMSMS security documents?

Posted: Mon Oct 15, 2012 11:31 am
by Recon
Hi,

I can't found or I can't search with right keywords any security documents witch are refer to CMSMS. My costumer want his company websites to be build with WordPress, but I we have agree that sites will be build with CMSMS. For this reason customer want security documents. I don't even know is there these kind document? Any links to tests? Or something?

BR

-R

Re: CMSMS security documents?

Posted: Mon Oct 15, 2012 8:29 pm
by Dr.CSS
You may notice we don't have a board dedicated to security problems, where as some of the other CMSs do because it is such an ongoing concern for them, we have someone who tests every version of CMSMS for any vulnerabilities and we fix them as soon as they are found...

Re: CMSMS security documents?

Posted: Tue Oct 16, 2012 5:57 am
by Recon
I have noticed and have fully trust to development team :) , but how convince my customer, who is not familiar with the CMSMS?

Any third party company's test where have compered different cms? Or some sentences from development team why cmsms don't have security issues?

-R

Re: CMSMS security documents?

Posted: Tue Oct 16, 2012 6:18 am
by Jos
You can check the announcements for new releases, count the times where is stated that some vulnerability has been solved. You won't find many on CMSms 8)

Re: CMSMS security documents?

Posted: Tue Oct 16, 2012 12:39 pm
by Jo Morg
5 years+ using it in sites. Never had an issue with CMSMS. The only time a site was compromised was a server problem not a CMSMS problem.

Re: CMSMS security documents?

Posted: Wed Oct 17, 2012 12:48 am
by manuel
Dear Recon,

I think this should do it ;D

http://secunia.com/community/advisories ... ade+Simple
http://secunia.com/community/advisories ... arch=cmsms
http://secunia.com/community/advisories ... =WordPress

Personally, i only experienced one single issue.
A content editor was working with an infected browser on her Mac.
Every time she edited a page, the infected browser inserted a javascript in the wysiwyg. (it replaced certain keywords with advertising links)
This was clearly not a cmsms issue and was fixed easily by reinstalling her browser.

Just keep everything more or less up to date and you should be fine (and make a backup once in a while ;D )

Greetings,
Manuel

Re: CMSMS security documents?

Posted: Wed Oct 17, 2012 6:02 am
by Recon
Thx Manuel, I will check those.


Jo Morg, like I said, this is FOR CUSTOMER, not for me. I can't say to my customer: "yes, this is what we need to use, because Jo Morg says on the forum, that he has use this for 5 years" ;)

-R

Re: CMSMS security documents?

Posted: Wed Oct 17, 2012 11:55 am
by Jo Morg
Recon wrote:Jo Morg, like I said, this is FOR CUSTOMER, not for me. I can't say to my customer: "yes, this is what we need to use, because Jo Morg says on the forum, that he has use this for 5 years" ;)
You can't? ??? :D ;) 8)
Heh! :P

Re: CMSMS security documents?

Posted: Wed Oct 17, 2012 5:13 pm
by Dr.CSS
You can always tell them I said it was safe to use and they are ID10Ts if they use anything else... ;)