osCommerce version 2.3.4 suffers from cross site request forgery and local file inclusion vulnerabilities.