Results 1 to 2 of 2
  1. #1
    Join Date
    May 2008
    Posts
    188
    Plugin Contributions
    0

    Default Search with a ( or ) in the query returns an invalid keywords error message

    Version 1.3.9h

    Any search term with the characters ( or ) returns an invalid keyword error.

    The issue is if any of these brackets have a space between them. For example Call Of Duty ( Wii Pre Owned ) generates an invalid keyword message where as Call Of Duty (Wii Pre Owned) doesn't.

    This is present in all of our zen sites and also in the default install / classic template.

    We're currently testing a mod that auto completes the search field but a lot of our products are worded in such a way that when they are searched for in this manner the invalid keyword error arises.

  2. #2
    Join Date
    Jun 2003
    Location
    Newcastle UK
    Posts
    2,896
    Blog Entries
    2
    Plugin Contributions
    2

    Default Re: Search with a ( or ) in the query returns an invalid keywords error message

    Hi,

    Can confirm the problem in 139/15.

    It is caused by some code that parses the keyword list in an attempt to find nested operators

    e.g "(word1 AND (word2 OR word3))"


    the same code can also in certain circumstances produce SQL errors (Thanks to RodG for pointing that out), although those SQL errors do not mean that injection is possible.

    Looking at this to see the best way to fix.

 

 

Similar Threads

  1. Replies: 8
    Last Post: 29 Apr 2012, 11:43 AM
  2. Linkpoint error message: Invalid XML
    By PortraitArtist in forum Built-in Shipping and Payment Modules
    Replies: 7
    Last Post: 1 Feb 2008, 12:01 AM
  3. Error Message GC Code Invalid
    By kmickus in forum Discounts/Coupons, Gift Certificates, Newsletters, Ads
    Replies: 5
    Last Post: 24 Dec 2007, 07:13 PM
  4. Search for manufacturers returns MYSQL Error
    By brad512 in forum Basic Configuration
    Replies: 4
    Last Post: 4 May 2007, 08:53 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR