Page 2 of 2 FirstFirst 12
Results 11 to 20 of 20
  1. #11
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    yes, the updates forum.
    Zen cart PCI compliant Hosting

  2. #12
    Join Date
    Sep 2006
    Posts
    29
    Plugin Contributions
    0

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    Ah.... You mean the big blue link that says "Click here to subscribe to these announcements."?

    Thanks!

  3. #13
    Join Date
    Aug 2004
    Posts
    262
    Plugin Contributions
    0

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    If we are running 2.6, should we apply these fixes?

  4. #14
    Join Date
    Jan 2004
    Posts
    66,450
    Plugin Contributions
    81

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    Okay ... Yes ... I'll go on record as saying ... yes ... everyone should apply these fixes.

    The line numbers may be different, and the content slightly different too. But the concept of the fix is the same.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #15
    Join Date
    Jan 2004
    Posts
    66,450
    Plugin Contributions
    81

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    Quote Originally Posted by sadie
    If we are running 2.6, should we apply these fixes?
    As for people running v1.2.6, you really should at least upgrade to v1.2.7 due to important security bugfixes applied to 1.2.7. That's in addition to this suggested fix, which is very minor in comparison to the fixes for 1.2.7
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #16
    Join Date
    Oct 2006
    Posts
    16
    Plugin Contributions
    0

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    Quote Originally Posted by IHaveADotCom View Post
    Ah.... You mean the big blue link that says "Click here to subscribe to these announcements."?
    wait.. what? where is that??d:
    Abstract Dreams, Real Infatuations.
    [X] MBS JEWELRY

  7. #17
    Join Date
    Aug 2005
    Location
    Trujillo Alto, Puerto Rico
    Posts
    1,550
    Plugin Contributions
    9

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    Look for the Patch in SourceForge.
    IDEAS Girl
    IDEAS Creative Group
    = Your image... our business!

  8. #18
    Join Date
    Jan 2004
    Posts
    66,450
    Plugin Contributions
    81

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    These fixes are all built-in to v1.3.6
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  9. #19
    Join Date
    Jun 2006
    Posts
    18
    Plugin Contributions
    0

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    Dr Byte,

    Does it mean that my recently installed 1.3.5 and patched as suggested earlier is basically up-to-date exceot for the new stylesheets?

    Thanks.

    henry

  10. #20
    Join Date
    Jan 2004
    Posts
    66,450
    Plugin Contributions
    81

    Default Re: [FIX] v1.3.5 XSS Exploits Found

    Quote Originally Posted by henrygoh View Post
    Dr Byte,

    Does it mean that my recently installed 1.3.5 and patched as suggested earlier is basically up-to-date exceot for the new stylesheets?

    Thanks.

    henry
    No. There were a LOT of fixes and feature improvements build in 1.3.6, especially address-form related fixes.
    But, as far as XSS security issues, yes, you are up-to-date on known security issues if you've applied both posted patches for 1.3.5.
    You still should be upgrading to 1.3.6 for the address-form benefits though.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 
Page 2 of 2 FirstFirst 12

Similar Threads

  1. Replies: 1
    Last Post: 2 Dec 2015, 07:31 PM
  2. xss fix vs google checkout - how do I do this?
    By fats1964 in forum General Questions
    Replies: 0
    Last Post: 5 Jul 2007, 05:04 PM
  3. Zero-Day XSS Security Fix
    By athena in forum General Questions
    Replies: 2
    Last Post: 12 Oct 2006, 08:17 PM
  4. Zero-Day XSS Security Fix (applies to all versions)
    By wilt in forum Zen Cart Release Announcements
    Replies: 1
    Last Post: 6 Oct 2006, 11:38 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg