Security Vulnerability Fixed In Version 1.1.5 and later
A vulnerability has been discovered in DFD Cart 1.1.4 and lower, that allows remote file injection and cross site scripting. Version 1.1.5 fixes this issue, and details on patching previous versions are in the "tracker" section of this sourceforge project.
Many thanks to those for finding and reporting this significant issue! :)
2007-09-24 20:43:41 UTC by taoteh1221