Get the book

Go Back   Zen Cart Support > News and Announcements > Zen Cart Release Announcements

Zen Cart Release Announcements Watch this forum for new releases and other important announcements.
Click here to subscribe to these announcements.

Closed Thread
 
Thread Tools Display Modes
Old 2nd October 2006, 02:31 AM   #1
wilt
Oji-san
 
wilt's Avatar
 
Join Date: Jun 2003
Location: Newcastle UK
Posts: 2,527
Default v1.3.5 Security Alert

We were informed recently of an XSS exploit in Zen Cart code.

I would like to thank Armorize technologies for responding so quickly to clarify the details of the exploit, especially Wayne Huang and Benson Wu of Armorize Technologies,

You can read more about the exploit and how to patch the files that are vulnerable at

http://www.zen-cart.com/forum/showth...700#post270700
wilt is offline  
Old 2nd October 2006, 06:51 AM   #2
DrByte
Sensei
 
DrByte's Avatar
 
Join Date: Jan 2004
Location: Ontario, Canada
Posts: 39,868
Default Re: v1.3.5 Security Alert

Zen Cart v1.3.5 XSS PATCH Released Oct 1, 2006
=================================================
To combat a reported XSS exploit vulnerability in Zen Cart, simply download the files from the patch ZIP and copy the enclosed /admin files for login.php and password_forgotten.php to your admin folder.

Remember, if you have renamed your admin folder, you will have to use *that*
folder name when copying/uploading.


File can be downloaded here:
http://sourceforge.net/project/showf...ease_id=444622

These fixes are NOT included in the main "full-fileset" zip.
Please apply these fixes AFTER unzipping the main full-fileset zip contents.

Alternatively, you may wish to apply the edits manually:
http://www.zen-cart.com/forum/showthread.php?t=47526
__________________
Zen Cart - putting the dream of business ownership within reach of anyone!
DrByte is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT +1. The time now is 03:52 PM.

Learn tips, tricks & secrets for your Zen Cart™
Sign up for our FREE Newsletter

Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content and Graphics Copyright (c) 2006, 2007, 2008, 2009, 2010 Zen Ventures, LLC - all rights reserved
Get Zen Cart E-Commerce Shopping Cart at SourceForge.net. Fast, secure and Free Open Source software downloads