OsCommerce can send out spam via the Mailinglist function, without login.
December 22nd, 2009
Comments off
osCommerce Online Merchant v2.2 RC2a has bug where one can send out spam through
http://domain.com/admin/mail.php/login.php
The proposed fix for oscmax is:
The fix in OscMax is:
http://code.google.com/p/oscmax2/source/detail?r=169
Also what is going on with these files here:
http://www.oscmax.com/blog/michael_s/security_notice_oscmax_204_released



