Issue #10: August 19, 2002

By Harald Ponce de Leon

August 19, 2002

Cross Site Scripting Vulnerabilities
Checkout And Order Security Issues
Search Engine Safe Urls
PHP3 Compatibility
Windows Date Problem Readdressed
Installation Module Updates For PHP-CGI Servers
Whos Online Logic Update
File Upload Standards

Cross Site Scripting Vulnerabilities

Tamura Toshihiko informed the developers forum of cross site scripting vulnerabilities existing in the 2.2-CVS codebase.

The posting can be read at:

https://www.oscommerce.com/community.php/forum,2/action,read/i,16332/t,16332

Fixes to the problem areas have been commited, but we are still working on a complete solution by validating user input.

Mattice has submitted a global fix which can be used on live stores, which can be read at:

https://www.oscommerce.com/community.php/forum,2/action,read/i,16432/t,16432

Checkout And Order Security Issues

Geoff Ford forwarded issues concerning the checkout procedure and how orders are made. It is possible for a customer to bypass the checkout procedure and head straight to the processing logic creating false orders.

This issue is most serious to those offering downloadable products that may be active to the customer as soon as an order has been falsely made.

A fix to the problem has been commited which can be seen here:

https://marc.theaimsgroup.com/?l=tep-commits&m=102975528416119&w=2

Search Engine Safe Urls

The logic to the Search Engine Safe Urls feature has been updated to properly parse all GET parameters, including the session ID where necessary.

This update may cause robots to cycle in a live store - we are currently discussing possible solutions to overcome this issue.

One nice solution mentioned is to start the session only when it is needed, for example when adding a product to the cart, and when a customer logs in or creates an account.

PHP3 Compatibility

Updates to the code logic have been made to bring back PHP3 compatibility. The estimated minimum for PHP3 versions is 3.0.7 - tests on bringing back the PHP3 compatibility were done on 3.0.11, the earliest version found for Windows servers.

Windows Date Problem Readdressed

Michael Burke has forwarded an update to the logic used for parsing dates prior 1970 on Windows based servers.

Dates prior 1970 should now be displayed correctly.

Installation Module Updates For PHP-CGI Servers

The installation module has been updated to allow for easier installation with servers that have PHP setup as CGI.

If you encounter any problems with the provided default path parameters during the installation procedure, please forward relevant information to the developers forum.

Whos Online Logic Update

The logic to the whos online feature has been updated to use only the necessary session variables from the customer on the catalog side.

Previously if the customer was viewing the store in a foreign language, selecting their entry on the Whos Online feature would use that language variable on the Administration Tool itself.

The logic calculating the customers shopping cart total has also been updated to calculate the right tax amount if display_price_with_tax is enabled. The [sub]total price shown is the exact price shown to the customer in their shopping cart box.

File Upload Standards

A new standard has been defined to handle file upload processing - which is compatible with all PHP versions, taking advantage of the features available of the PHP version in use.

The API documentation for this standard will soon be added to the CVS repository.

 

Recent posts

Time limited offer to mark the arrival of osCommerce v4!

May 24, 2022
Valuable REWARDS to all Subscribers of osCommerce newsletter:   - 10 native osCommerce applications +   - discounted osCommerce hosting for 1 shop Subscribe now ...

osCommerce v4 Beta 2 Released

January 26, 2022
osCommerce v4 Beta 2 has been released today! Current Beta is closer to the planned release version. We have removed a number of add-ons to simplify the installation. They will be re-instated via the App store, most of them free. Beta 2 comes with: - installation tool - 2 demo front ends - osCommerce back end - data import tool to migrate data from old osCommerce 2.x - instructions on how to submit your feedback Download links have been emailed to all Beta testers. If you have not received your link, please check your "spam" folder just in case, and contact us via this Forum to have the link re-sent to you. If you wanted to try Beta 2 but didn't sign up - get in touch with us via the Forum or via the Contact form on the website and we will sort it for you. osCommerce v4 will be released shortly as a powerful modern modular optimised FREE open source Ecommerce solution! Kind regards, osCommerce team   ...

osCommerce v4 Beta 1 Released

November 17, 2021
osCommerce v4 Beta 1 has been made available to a limited number of first reviewers today. We will work with the feedback we receive over the next couple of weeks, and will release Beta 2 to registered Beta-testers in early December 2021. Want to become a Beta tester? Contact us via the main website to register your interest now and receive access to Beta 2 in December! Providing we continue to receive reasonable feedback from the Beta testers we are looking to launch osCommerce v4 in early January 2022. Keep checking the Forums for updates. The wait is over!   ...

osCommerce v4 features: Order Editor, Gift Vouchers, Loyalty points, Currencies and Rounding

March 19, 2021
Working through the feature list of osCommerce v4: Order Editor and MOTO orders: https://forums.oscommerce.com/topic/496930-order-editor/?tab=comments#comment-1821801 Gift Vouchers: https://forums.oscommerce.com/topic/496929-gift-vouchers/?tab=comments#comment-1821800 Loyalty points: https://forums.oscommerce.com/topic/496924-loyalty-or-bonus-points/?tab=comments#comment-1821793 Currencies and Rounding: https://forums.oscommerce.com/topic/496921-currencies-and-rounding/?tab=comments#comment-1821738 Have any questions or comments? Feel free to post them here! Questions about osCommerce shall be emailed to  hello@oscommerce.com Development Partners and Beta Testers are always welcome! Please sign up via our  Contact Page . We will notify you when the Beta version becomes available (likely in June 2021). Development Partners - we will make preview versions available to you, please indicate your interest when signing up for the Beta Program.   ...

osCommerce v4 updates: Payments, Shipping, Shipping Labels, Order Totals

March 12, 2021
Update on osCommerce v4 feature list Payment methods: https://forums.oscommerce.com/topic/496907-payment-methods/ Shipping solutions: https://forums.oscommerce.com/topic/496910-shipping-methods/ Shipping labels: https://forums.oscommerce.com/topic/496911-shipping-labels/ Order structure management: https://forums.oscommerce.com/topic/496912-order-structure-totals-modules/ Have any questions or comments? Feel free to post them here! Questions about osCommerce shall be emailed to  hello@oscommerce.com Development Partners and Beta Testers are always welcome! Please sign up via our  Contact Page . We will notify you when the Beta version becomes available (likely in June 2021). Development Partners - we will make preview versions available to you, please indicate your interest when signing up for the Beta Program.   ...

osCommerce v4 news: SEO and Menu Editor

March 06, 2021
osCommerce v4 features continue to be revealed. Today we published preview of on-site SEO system in osCommerce v4 on our Forums: https://forums.oscommerce.com/topic/496884-search-engine-optimisation-seo/ and its Menu editor: https://forums.oscommerce.com/topic/496886-menu-editor/ Questions about osCommerce shall be emailed to  hello@oscommerce.com Development Partners and Beta Testers are always welcome! Please sign up via our  Contact Page . We will notify you when the Beta version becomes available (likely in June 2021). Development Partners - we will make preview versions available to you, please indicate your interest when signing up for the Beta Program.   ...

osCommerce v4 news: Multiple Design Templates and Template Designer

March 02, 2021
osCommerce v4 features are being revealed. Today we share information about Design Templates and Template Designer of osCommerce v4 on our Forums: https://forums.oscommerce.com/topic/496786-multiple-design-templates-and-built-in-designer/ Questions about osCommerce shall be emailed to  hello@oscommerce.com Development Partners and Beta Testers are always welcome! Please sign up via our  Contact Page . We will notify you when the Beta version becomes available (likely in June 2021). Development Partners - we will make preview versions available to you, please indicate your interest when signing up for the Beta Program.   ...

New management and osCommerce v4

February 19, 2021
Assert Record Run SnapTest ...

Phoenix v1.0.7.15

February 10, 2021
v1.0.7.15 is a bugfix release. This should be considered the second release candidate for 1.0.8.0. Easy Updates Easy update zip and instructions are provided in the Phoenix Club for every minor and major update. Going from version to version could not be easier - you are supported by the Phoenix Team,  Certified Developers , and other Shop owners. This update takes 100 seconds from start to finish. Have your say at the Phoenix Club Instead of waiting for a perfect tomorrow, help us make a better today by joining the  Phoenix Club . Thank you Thank you to all Shop owners and Developers who are supporting the Project - you allow Phoenix to fly high and burn brightly.   ...

Phoenix v1.0.7.14

January 26, 2021
v1.0.7.14 is the final development release of the 1.0.7.* series. It finishes the templates system, including the ability to override the HTML templates and the language files. This should be considered the first release candidate for 1.0.8.0. Easy Updates Easy update zip and instructions are provided in the Phoenix Club for every minor and major update. Going from version to version could not be easier - you are supported by the Phoenix Team,  Certified Developers , and other Shop owners. This update takes 100 seconds from start to finish. Have your say at the Phoenix Club Instead of waiting for a perfect tomorrow, help us make a better today by joining the  Phoenix Club . Thank you Thank you to all Shop owners and Developers who are supporting the Project - you allow Phoenix to fly high and burn brightly.   ...
Products