Zen Cart Security Announcement – George Susini
The Zen Cart team announced a vulnerability has been discovered in the admin section of v1.3.8 (and previous versions). To take advantage of this vulnerability any attacker must know the URL of your admin section.
A security patch has been released along with recommendations for securing your site .
To install the security update you will need to do the following:
- rename the /admin folder and modifying the configure.php file
- Load the security patch files
- Modify the /includes/functions/html_output.php
The security patch and instructions are available at the Zen Cart Site -
Zen Cart Security update link
http://www.zen-cart.com/forum/showthread.php?t=130161
George Susini – Small Business Web Design, ecommerce, SEO and Social Marketing