11/27/15 Zen Cart Security Patch


    

25.00

Add to Cart:

1. Problem with /ajax.php in v1.5.4 only - Severity: High
In Zen Cart v1.5.4 the /ajax.php file has a vulnerability which can be used to cause a server exploit under very specific conditions.
Requires replacing the ajax.php file with new one

Below are some additional lower-severity patches affecting prior versions, which should be reviewed carefully for your site, to merge with existing customizations you may have made:

2. XSS problem for unsanitized comment field - Severity: Medium
In Zen Cart versions up to and including v1.5.4 an XSS problem exists with the order-comments field.
XSS problems are where someone can drop in executable/javascript code that can cause problems later when that content is output back to the screen.
Requires patching /includes/modules/pages/checkout_confirmation/header_php.php,

3. Failed customer login puts password back in input box - Severity: Low
When attempting a login with an invalid password, the resulting response contains that invalid password.
Requires patching /includes/functions/html_output.php file
 


Customers who bought this product also purchased...

Shopping Cart

Your cart is empty.

Customer Reviews

GOD"S HEAVEN SENT MIRACLE

I wish I would have found Judy years and years ago. Instead I was using someone else who after spending 1,000s with them only pretended to know zen...
Read More ->


Genius

The best money that I have ever spent. My website had been at a standstill for the past 3 months...Judy was able to take my list+ (I constantly...
Read More ->


5 Star Rating

No, I take that back, she gets a 10 Star rating!!! I have been in business a long time and used a lot of IT people during that time, but Judy...
Read More ->


Judy Rocks!!

Judy is absolutely the BEST! She did in less than three days what another person had been working on for three months and still didn't have it up and...
Read More ->


Judy - Zen Cart Goddess!

If you've got Zen Cart, you GOTTA get Judy! We discovered her a couple of years ago when our former web designer went AWOL. Not only did she upgrade...
Read More ->


Who's Online

There currently are 16 guests online.
Copyright © 2004 - 2021 ZenCart Ecommerce Website Design
Zen Cart Templates Zen Cart Guru
Powered by Zen Cart