Archive for July, 2008

Security Bulletin - 20080703

During internal audit activities X-Cart have identified several moderate security vulnerabilities.
DESCRIPTION and IMPACT
In all X-Cart versions:
1. A malicious provider may ask the store administrator to use special symbols during creation of a provider account. In this case the provider can get access to the store files from the Files directory (or even outside of it).
2. [...]

Read More..>>