OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Security of osCommerce

From: Joel Merrick (joelservicestyle.com)
Date: Tue Jan 18 2005 - 11:18:59 CST


Hi,

I'm wondering if anyone can tell me about the current security status of
the MS2.2 release of osCommerce?

I understand that there have been XSS vulnerabilities and DOS exploits,
heve these been fixed in the MS2.2 downloadable from the site?

Any help appreciated, the forums deleted my post because it contained an
URL to a Security foucussed osCommerce project (nothing getting sold
though!). Open source? :)

--
Joel Merrick

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQBB7UUDAdG+sSilvKQRAlWVAKC8SoI5iLGJqPPHUv6Kpnd2bQsoBwCeKE6D
HY5uP7udHUiKoApaxCqJSUw=
=IUvy
-----END PGP SIGNATURE-----