I assure you that I'm tightening the security for bitmunchies, as well as many of my other sites. :-/ I was not aware that OSCommerce had a reputation for lax security, but I'm increasingly considering a switch. It has many other shortcomings.
I have had 2 servers get rooted because of friends I hosted using OSC.
Browse the security section of their forums, there are a few key things to make note of.
I now recommend Ecwid to anyone who is looking for something free, simple, and secure.
Though I doubt there is an easy way to make it work with bitcoin.