VirtueMart - Open Source eCommerce Software

Security Patch for VirtueMart 1.1.7 and below Print E-mail
Written by Soeren Eberhardt-Biermann   
Friday, 18 February 2011 16:05

Some days ago the VirtueMart Team was informed of another security problem, found by Steven Seely of Stratsec. That's why we have made available a patch for VirtueMart 1.1.7 to fix this security issue. All VirtueMart users are urged to apply this patch as soon as possible. How to do that: Follow the instructions in our Security Bulletin 2011-02-18.

 

About this patch
VirtueMart 1.1.7a is a patch that fixes an SQL injection problem that was revealed after VirtueMart 1.1.7 had been released. Read more about it in our Security Bulletin 2011-02-18.

Thanks to Francesco for developing and creating this patch package so quickly!

Comments (4)add comment
0
Stnly: 1.1.3
Should I use the patch with VM 1.1.3 (via FPT upload)?
1

February 20, 2011
Votes: +0
0
D O'Brien: Which files are affected
Hi, I have a heavily modified vm site and implement upgrades manually. Please can you inform which files have been updated (and possibly link the new files also)?

Regards,
David
2

February 21, 2011
Votes: +1
Soeren Eberhardt-Biermann
Sören: Update
The patch package contains one file, besides update.xml. It's ps_module.php. You can use that file to patch versions lower than VM 1.1.7.
3

February 21, 2011
Votes: +0
0
Clauser: Patch for 1.1.4
downloaded patch 1.1.7a but when trying to upload, it says in the preview "patch for 1.1.7" I got 1.1.4 , is manually replace ps_module the way to go? what about "virtuemart.php" sercurity patch?
thanks
4

March 02, 2011
Votes: +0

Write comment

busy
Last Updated on Friday, 18 February 2011 18:29
 

Subscribe to our News

Enter your email address:

Delivered by FeedBurner

Virtuemart Newsfeed Counter