yes, the updates forum.
Ah.... You mean the big blue link that says "Click here to subscribe to these announcements."?
Thanks!![]()
If we are running 2.6, should we apply these fixes?
Okay ... Yes ... I'll go on record as saying ... yes ... everyone should apply these fixes.
The line numbers may be different, and the content slightly different too. But the concept of the fix is the same.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
As for people running v1.2.6, you really should at least upgrade to v1.2.7 due to important security bugfixes applied to 1.2.7. That's in addition to this suggested fix, which is very minor in comparison to the fixes for 1.2.7Originally Posted by sadie
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Abstract Dreams, Real Infatuations.
[X] MBS JEWELRY
Look for the Patch in SourceForge.
IDEAS Girl
IDEAS Creative Group = Your image... our business!
These fixes are all built-in to v1.3.6
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Dr Byte,
Does it mean that my recently installed 1.3.5 and patched as suggested earlier is basically up-to-date exceot for the new stylesheets?
Thanks.
henry
No. There were a LOT of fixes and feature improvements build in 1.3.6, especially address-form related fixes.
But, as far as XSS security issues, yes, you are up-to-date on known security issues if you've applied both posted patches for 1.3.5.
You still should be upgrading to 1.3.6 for the address-form benefits though.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.