Security osCommerce 2.3.4 Local File Inclusion / Cross Site Request Forgery February 18, 2016 007admin osCommerce version 2.3.4 suffers from cross site request forgery and local file inclusion vulnerabilities.