The vulnerable code is located under cart.php which contains:
Code: 
    if ( $a == "add" )
    {
       $templatefile = "configureproductdomain";
        ....etc
    }

    if ( $a == "login" )
    {
        $templatefile = "login";
        ....etc
    }
     ...
    outputClientArea( $templatefile, $nowrapper );
    # outputClientArea function will display
    "./templates/orderforms/cart/{$templatefile}.tpl"
downote Reviewed by downote on . WHMCS Security Exploit+Patch Patch Your WHMCS Before you are HACKED! Courtesy Rating: 5