[sendcard] Important sendcard vulnerability discovered

  • From: Sendcard <peter@xxxxxxxxxxxx>
  • To: sendcard@xxxxxxxxxxxxx
  • Date: Thu, 03 Aug 2006 22:27:01 +0100

Dear all,

Today I was informed of a sendcard vulnerability which allows an 
attacker to execute malicious code on your website.  I have released 
a patch to fix the problem, and strongly advise you to upgrade as 
soon as possible!

To fix the problem, save the file at 
http://www.sendcard.org/temp/prepend.phps to your hard drive as 
'prepend.php'.  Copy this file to sendcard/admin (where sendcard is 
the name of the directory you installed sendcard into), and overwrite 
the existing file prepend.php.

Your site is now secure.

To complete the job, log into the admin area and click on the 
'Configure' link in the left-hand green menu.  Scroll down until you 
see sendcard's version number, and change this to 3.4.1.

Kind regards,
Peter

-- 
sendcard - The free open source PHP e-card solution
http://www.sendcard.org   

--
You  are subscribed to the sendcard mailing list because you signed up for it.  
To unsubscribe, please send an email to sendcard-request@xxxxxxxxxxxxx with 
'unsubscribe' in the Subject field.

Other related posts:

  • » [sendcard] Important sendcard vulnerability discovered