ropu, et al-
The Zen Cart team just posted a fix for XSS vulnerabilities in Zen Cart 1.37. One of the files updated is /admin/orders.php. That file is distributed in the Google Checkout mod, so please remember to include the fix in the next mod release.
For info on the patch and some background:
http://www.zen-cart.com/forum/showthread.php?t=64115
Backgound: http://www.zen-cart.com/forum/showthread.php?t=63677
Woody
Bookmarks