X-Cart/Smarty Security Issue
Saturday, April 26, 2008
Smarty, the templating system used by x-cart, has released an upgrade to Smarty 2.6.19 which addresses a vulnerability that has the possibility to allow your x-cart to be exploited.
This x-cart vulnerability can be addressed as follows:
- Download this new file: modifier.regex_replace.php
- Backup this file on your x-cart: path-to-x-cart/Smarty-2.6.12/plugins/modifier.regex_replace.php
(Note the Smarty-2.6.12 directory may differ depending on your x-cart version) - Upload the new file in place of this backed-up file.