Author Topic: CRE Loaded Link Page Vulnerability with beta Fix.  (Read 11896 times)

0 Members and 2 Guests are viewing this topic.

David M. Graham

  • Administrator
  • Sr. Member
  • *****
  • Offline Offline
  • Posts: 380
  • Karma: 12
    • View Profile
    • osCommerce University
CRE Loaded Link Page Vulnerability with beta Fix.
« Reply #1 on: June 01, 2008, 04:25:30 PM »
Recently, a Cross Site Scripting vulnerability was discovered in the CRE Loaded Links and Links Submit pages.   This affect all versions before and including 6.2.13.1

The attached files provide a fix for this issue.



David