Security Patch 28th August 2006, All must apply this patch! |
IMPORTANT NOTICE: These forums have been provided for customer to customer support/discussion. CubeCart staff members may not frequent these forums regularly so please do not expect an official reply. If you have a sales or support question please submit a ticket via our helpdesk and a member of staff will get back to you during office hours.
![]() ![]() |
Security Patch 28th August 2006, All must apply this patch! |
Aug 28 2006, 12:26 PM
Post
#1
|
|
![]() Group: Staff Posts: 4,068 Joined: 9-April 03 From: Bishops Stortford, UK Member No.: 1 |
Multiple XSS vulnerabilities, file inclusion and MySQL Injection (on servers with Register Globals On) have been bought to our attention in all versions up to 3.0.12.
Please find the patch attached to this announcement which contains a change log for manual upgrade as well as the patched files. We take any reported security issues with utmost importance and investigate at the first possible opportunity. This dedication can be seen by the fact our office was officially close today due to the August Bank Holiday. We have released a patch within a few hours of receiving the report. Many thanks to all those who have been involved. We will release 3.0.13 later which includes this patch along with minor other changes. If you have already patched your store upgrade is not essential. *3.0.13 will be released tomorrow (Tuesday 28th August) if you currently download and install 3.0.12 or lower you will need to apply this patch* *3.0.13 will be delayed until we have a full 3rd party professional security audit carried out on CubeCart* This post has been edited by Al: Aug 29 2006, 11:00 AM
Attached File(s)
|
|
|
|
![]() ![]() |
|
Lo-Fi Version | Time is now: 9th February 2010 - 02:36 AM |