Hero Zzyzzx Posted November 11, 2002 Posted November 11, 2002 Hey all. I'm checking this out as an upgrade for a shop I built that's doing a brisk business selling coins online, and I have one major question that wasn't solved by searching the forum. Has the code injection bug mentioned here been fixed yet? I was burnt once when I trusted PHPNuke (it got hacked. . .) now I'm INFINITELY more paranoid about trusting other's code. Thanks in advance! I'm a full-time mod_perl/PHP developer, and before I do an audit of the code I want to see how responsive the team is to security issues (and yes, I know that web security is more of an art than a science, and it can be a compromise between functionality and security.).
Trusten Posted November 11, 2002 Posted November 11, 2002 that was version 2.1. wasn't it? i think this issue has long since been addressed in version 2.2. but don't quote me. that file doesn't exist in 2.2 as far as i remember.
mattice Posted November 11, 2002 Posted November 11, 2002 Yes it was 2.1 and is fixed. 2.2 still has CSS issues (Cross Site Scripting) afaik. See suggestions & fixes here: http://www.oscommerce.com/community.php/weekly,75 "Politics is the art of preventing people from taking part in affairs which properly concern them"
Hero Zzyzzx Posted November 11, 2002 Author Posted November 11, 2002 Arrgh. There's still CSS issues, huh? Thanks for the frank warning. That would makes me nervous, personally. Oh well, thanks for your help. I was actually kind of surprised not to see a security forum in these boards. . .
Aragon127 Posted November 11, 2002 Posted November 11, 2002 I thought the CSS issues were fixed in early August? Arrgh. There's still CSS issues, huh? Thanks for the frank warning. That would makes me nervous, personally. Oh well, thanks for your help. I was actually kind of surprised not to see a security forum in these boards. . .
mattice Posted November 11, 2002 Posted November 11, 2002 I didn't check... hence the "AFAIK"... Could not find anything but the quoted news though but I could have overlooked it... "Politics is the art of preventing people from taking part in affairs which properly concern them"
Recommended Posts
Archived
This topic is now archived and is closed to further replies.