A critical security vulnerability has been identified and corrected in AspDotNetStorefront ML, ML/64, PRO, and Standard versions 7.0.1.3 through 7.0.2.5.
In response, we have released 7.0.2.5 Service Pack 1 as of 05/07/2008 which contains fixes for the vulnerability as well as other functionality updates.
While there are no confirmed reports of the vulnerability being exploited, it is critical that all customers using affected versions of AspDotNetStorefront update to the 7.0.2.5 Service Pack 1 build as soon as possible to ensure their AspDotNetStorefront website continues to operate safely and securely.
Affected Versions:
* AspDotNetStorefront ML v7.0.1.3 – v7.0.2.5
* AspDotNetStorefront ML/64 v7.0.2.5
* AspDotNetStorefront PRO v7.0.2.1
* AspDotNetStorefront STANDARD v7.0.2.1
Customers may download version 7.0.2.5 (which contains the service pack 1 updates) from their MyLicenses page at http://www.aspdotnetstorefront.com/mylicenses.aspx.
Due to the nature of the update, it is not possible to release patches for previous versions of the software.
Customers using heavily customized versions of AspDotNetStorefront should contact our support department at support@aspdotnetstorefront.com or via https://support.aspdotnetstorefront.com. To ensure timely responses, please include your website’s URL and your AspDotNetStorefront order number.
For the protection of our customers, AspDotNetStorefront as a matter of policy and safety does not disclose details regarding any security vulnerability, and any requests for specific details will be not be answered. We appreciate your understanding.
Sincerely,
The AspDotNetStorefront Team
Important notice to customers using versions prior to 7.0
AspDotNetStorefront is no longer releasing updates of any kind for versions of AspDotNetStorefront prior to version 7.0. Versions released prior to version 7.0, released on November 24th, 2006 are not VISA PABP certified, and as such, customers using these older versions may soon be in violation of payment card industry requirements if they do not update their sites to v7.0 releases. It is therefore recommended that customers using versions 6.2 or earlier contact our sales department to discuss upgrade options. Sales can be reached Monday through Friday, 9am - 8pm Eastern Time.