Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

SQL Injection help:( - Advice


helpme:(

Recommended Posts

Posted

Looking for a contribution that will allow customers to leave feedback or a testimonial. There are a couple feedback contributions, but they are not well developed. We like the customer testimonial add-ons, but we heard that they are known for sql injections and is a security issue when installed in OSc.

 

Have seen all the different feedback and customer testimonial contributions, but would appreciate any ideas on which add-on we should use.

 

 

Thanks in advance. :)

Posted

That contribution had an update a while back which should have fixed it.

 

 

http://www.oscommerce.com/community/contributions,839

 

 

 

But the most secure option would be to just let customers email you testimonials through the contact form, or something similar. Then you can handpick testimonials to put on your site. This also prevents malicious users from saying bad things in the testimonials hoping you won't notice.

Posted

Thanks Terminum :) .

 

Thought of just using the contact form but then again it might become a hassle to always edit an extra page just to add the feedback the shop gets in.

 

Any more iDeas. Any1?

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...