Subdreamer Security Status


Subdreamer has had an excellent track record, only effected by one security vulnerability during the lifetime of the product. That flaw was quickly patched. (Subdreamer Pro and Subdreamer Light were both effected by SQL injection vulnerabilities, Subdreamer Light is discontinued and should not be used on production websites. Subdreamer Pro and Subdreamer Basic are free of any know security issues.)

Security problems are hard to diagnose but 99% of the time entry to a site is through a known issue which is not patched, ie. outdated files.

A common Subdreamer security issue is users leaving old skins uploaded to their server in the skin directory and not updating them per earlier security warnings. The skin files even if not active are still there and can be used to gain entry to the site. Anyone that has old skins uploaded, even if you are not using them, should delete them from the server or update them. All skins including current/active skins that you have installed, if downloaded prior to June 2006 MUST be updated.

See Skin security notice here .

 

You can follow Subdreamer CMS Secunia Advisories here.

Current Status:

Subdramer Pro 2.x Security Status

Subdreamer Security Status