|
|||||||
| Zen Cart Release Announcements Watch this forum for new releases and other important announcements. Click here to subscribe to these announcements. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Oji-san
Join Date: Jun 2003
Location: Newcastle UK
Posts: 2,503
|
We were informed recently of an XSS exploit in Zen Cart code.
I would like to thank Armorize technologies for responding so quickly to clarify the details of the exploit, especially Wayne Huang and Benson Wu of Armorize Technologies, You can read more about the exploit and how to patch the files that are vulnerable at http://www.zen-cart.com/forum/showth...700#post270700 |
|
|
|
|
#2 |
|
Sensei
Join Date: Jan 2004
Location: Ontario, Canada
Posts: 38,586
|
Zen Cart v1.3.5 XSS PATCH Released Oct 1, 2006
================================================= To combat a reported XSS exploit vulnerability in Zen Cart, simply download the files from the patch ZIP and copy the enclosed /admin files for login.php and password_forgotten.php to your admin folder. Remember, if you have renamed your admin folder, you will have to use *that* folder name when copying/uploading. File can be downloaded here: http://sourceforge.net/project/showf...ease_id=444622 These fixes are NOT included in the main "full-fileset" zip. Please apply these fixes AFTER unzipping the main full-fileset zip contents. Alternatively, you may wish to apply the edits manually: http://www.zen-cart.com/forum/showthread.php?t=47526
__________________
Zen Cart - putting the dream of business ownership within reach of anyone! |
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|