This section contains all security patches released to date for Squirrelcart and Squirrelcart PRO. Unless otherwise stated, patches are not cumulative. Patches for your version should be applied in the order they were released.
|
SC090122 - XSS/CSRF vulnerability patch
|
2009-01-22 13:36:00
This patch secures against a XSS (Cross Site Scripting) and CSRF vulnerability. Versions 2.6.4 - 2.0.0 are vulnerable. |
|
SC081209 - XSS vulnerability patch
|
2008-12-09 19:29:00
This patch secures against a XSS (Cross Site Scripting) vulnerability. Versions 2.6.0 - 2.6.3 are vulnerable. |
|
SC080814 - Remote PHP execution patch
|
2008-08-14 15:22:00
This patch secures against possible remote PHP execution attacks for Squirrelcart. Versions 1.3.0 through 1.6.3 are vulnerable. The vulnerability fixed by this patch is similar to the one reported in SC060825 but not identical. |
|
SC071022 - SQL injection vulnerability patch
|
2007-10-22 17:35:00
This patch secures against SQL injections discovered on 10/22/2007 in versions 1.2.0 through 2.4.5. It is a critical patch and should be applied to all affected versions immediately. |
|
SC070718 - XSS vulnerability patch
|
2007-07-18 18:46:00
This patch secures against (2) XSS (Cross Site Scripting) vulnerabilities. Versions 1.5.5 through 2.4.4 are vulnerable. |
|
SC060825 - Remote PHP execution patch
|
2006-08-25 12:36:00
This patch secures against possible remote PHP execution attacks for Squirrelcart. Versions 1.3.0 through 2.1.4 are vulnerable. The vulnerability fixed by this patch is similar to the one reported in SC060515 but not identical. |
|
SC060515 - Remote PHP execution patch
|
2006-05-17 18:43:00
This is the 2nd release of a patch to secure against possible remote PHP execution attacks for Squirrelcart. Versions 1.0.6 through 2.2.2 are vulnerable. This patch works for versions 1.0.6 - 2.1.4. For versions 2.2.0 - 2.2.2, we recommend you upgrade to the latest release. |
|
SC050407 - SQL Injection Patch
|
2005-04-07 14:09:00
This is a patch to secure against possible SQL injection attacks for Squirrelcart versions 1.5.x and prior. Newer versions do not need this patch. More information about this can be found in this forum post. |