iHTML Merchant Feedback Form Security Vulnerability

Solution:
Apply the security patches found at:

http://www.ihtmlmerchant.com/support_patches_feedback.htm

Or use this temporary fix:

<!--- http://www.team-asylum.com -->
<iEQ name="brac" value=<iSTRIN SRC=":email" DST="<">>
<iIF NOTCOND=<iSTRNICMP SRC=:brac DST="0">>
For security reasons, your message was not sent.<br>Please verify that you
entered your email address correctly, by going <a
href="javascript:history.back(1)">back</a><br>
<iinclude name="template/footer.ihtml">
<iSTOP>
</iIF>



 

Privacy Statement
Copyright 2010, SecurityFocus