Results 1 to 4 of 4
  1. #1
    Join Date
    Jun 2011
    Location
    Cariacica, Brazil
    Posts
    12
    Plugin Contributions
    0

    Default [Not a bug] coupon help exploit

    This is a report from one of our customers:
    - I log-in and go to My Account section.
    - Then I choose an old order that contains a coupon previously purchased from some promotion ( https://www.example.com/store/index....rder_id=219960 )
    - I scroll down until I can find the "Discount Coupon: xxxxxx" message which appears highlighted. If I do left-click on it, I can open a pop-up menu. I select 'copy link location'.
    - I open a txt file and I paste. I get this: javascript:couponpopupWindow('http://www.example.com/store/index.php?main_page=popup_coupon_help&cID=7581')
    - If I delete some data, then I get this: http://www.example.com/store/index.p..._help&cID=7581
    - Then I make a copy that link and paste into the address bar of my browser. If I change the number by mantaining the rest of the address, I can free have access to all the coupons.
    - Yesterday, I downloaded two products with two coupons that I randomly grabbed with the method explained above. Also, I deleted them inmediately.

  2. #2
    Join Date
    Sep 2008
    Posts
    210
    Plugin Contributions
    21

    Default Re: coupon help exploit

    If problem is in popup_coupon_help, you should to go to includes/modules/pages/popup_coupon_help and check the code.
    Our Site: http://zucando.com
    Marketing Plugins: Marketing Modules
    Free Response Templates: Responsive Templates

  3. #3
    Join Date
    Jan 2007
    Location
    Los Angeles, California, United States
    Posts
    10,023
    Plugin Contributions
    32

    Default Re: coupon help exploit

    Quote Originally Posted by diego.s.v View Post
    This is a report from one of our customers:
    before you go tearing through the code (without any idea of what it is you should be looking for..) you might want to state what version of Zen Cart you are running..
    My Site - Zen Cart & WordPress integration specialist
    I don't answer support questions via PM. Post add-on support questions in the support thread. The question & the answer will benefit others with similar issues.

  4. #4
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: coupon help exploit

    I question the idea of "this is an exploit" ...

    What stops me from going to Dell or Amazon or where ever and typing very very fast until I hit a valid coupon code for my order?

    Eventually I would find the right combination of letters/numbers ...

    If you are concerned as you use Discount Coupons with codes such as:
    Oct1
    Oct2
    Oct3

    then don't do that ...

    Get a little more creative on the Discount Codes and they are not so easily guessed but still give you a trail on how you track your Discount Coupons ...
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today: v1.5.5]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

 

 

Similar Threads

  1. Replies: 9
    Last Post: 16 Aug 2007, 04:55 PM
  2. Replies: 10
    Last Post: 10 Aug 2007, 09:47 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR