Security osCommerce 2.3.4 Local File Inclusion / Cross Site Request Forgery February 18, 2016 007admin Leave a comment osCommerce version 2.3.4 suffers from cross site request forgery and local file inclusion vulnerabilities.