Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

shopping cart flaw


stevennickelby

Recommended Posts

Posted

I was testing the website and I found that,

 

if a customer is checking out and they are up to...

https://website/checkout_confirmation.php

 

then they paste in their browser...

https://website/checkout_process.php

 

then,

 

https://website/checkout_success.php

 

will load up....hence the customer has placed an order with out paying for it!!

 

The order is now in the system

 

does any one know of a script to stop this from happening?

 

so they can't skip the payment modules?? :(

please help

Posted
I was testing the website and I found that,

 

if a customer is checking out and they are up to...

https://website/checkout_confirmation.php

 

then they paste in their browser...

https://website/checkout_process.php

 

then,

 

https://website/checkout_success.php

 

will load up....hence the customer has placed an order with out paying for it!!

 

The order is now in the system

 

does any one know of a script to stop this from happening?

 

so they can't skip the payment modules?? :(

please help

 

There is a whole discussion going on about this. search "order hack".

 

Sheri

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...