Oscommerce 2.3.4 XSS / HPP / File Inclusion

Oscommerce version 2.3.4 suffers from cross site scripting, HTTP parameter pollution, and local file inclusion vulnerabilities.