PROBLEM:
A security vulnerability (SQL injection attack) on the user login screen has been identified on Q-Shop 2.x.
This vulnerability also affects a previous security patch announced in Article_6CC33.
RESOLUTION:
Customers that have not applied the Q-Shop 2.5A security update should do so.
Customers that have applied the patch should download it again and update /users.asp and /inc/userlib.asp to protect against this vulnerability.
To obtain the security update for Q-Shop 2.5 rev A, please contact support@quadcomm.com indicating your order id.