Drupal has a pretty dedicated group of security pros who receive, verify, fix, and report bugs in their software. Over the 3 years I've used drupal, I've not personally suffered from any exploits in the software, but I also make sure to keep my modules updated.
Ubercart has security bulletins as well, and the team does a pretty good job of releasing security updates when those bulletins are released.
So basically, tell your client that as long as you keep your system updated you should 'knock-on-wood' be protected from most vulnerabilities.
There is a good list of sites using ubercart here: http://www.ubercart.org/site



Joined: 08/08/2007