Results 1 to 5 of 5
  1. #1
    Join Date
    Jul 2006
    Posts
    154
    Plugin Contributions
    0

    Default Question about XSS patch upgrade

    Hi...

    I have a custom file in my templates directory which is affected by the XSS patch. I need to manually alter the lines in this file "tpl_account_history_info_default.php" -- I was reading through the patch upgrade code that was left by Dr. Byte, but I didn't see any manual edits for this file. What lines need to be changed for the XSS patch? (If I missed this somehow I apologize ahead of time).

    Many thanks as always for your help and guidance.

    Kinget

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Question about XSS patch upgrade

    The fastest way to find out what exactly has changed, is to compare the original against the new, and then merge the differences.
    A tool such as WinMerge is extremely handy for this.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Jul 2006
    Posts
    154
    Plugin Contributions
    0

    Default Re: Question about XSS patch upgrade

    Thank you for this, however, I made lots of changes in that particular file, so there are a lot of changes and I think the Winmerge at this point really would be not that much help. Is it just one little line as you stated in the other thread? It would be very much help to me...I really don't have a lot of time or seeing availability to sit and compare.

    Thanks for your help.
    Kinget

    Quote Originally Posted by DrByte View Post
    The fastest way to find out what exactly has changed, is to compare the original against the new, and then merge the differences.
    A tool such as WinMerge is extremely handy for this.

  4. #4
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Question about XSS patch upgrade

    With the thousands of lines of code I look at each day, the only way for me to identify what's changed is to do the same comparison I recommended. I don't always remember the details off the top of my head, but I know how to find them.

    Instead of first comparing your customized file, compare the original template_default version of the file against the new/patched template_default version of the file. That should show you the differences.

    Then you can apply those differences to your customized file.


    This is the very same procedure that should be followed to upgrade an entire site ... one file at a time.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Jul 2006
    Posts
    154
    Plugin Contributions
    0

    Default Re: Question about XSS patch upgrade

    Hi Dr. Byte,

    I downloaded the program as you suggested, and it didn't detect any changes in the XSS patch on that file. Interesting, because this store was downloaded and installed a while ago. I'm going to compare other files....thanks as always for your help.

    Kinget

 

 

Similar Threads

  1. XSS Flaw Patch
    By wilt in forum Zen Cart Release Announcements
    Replies: 0
    Last Post: 8 Oct 2012, 01:48 PM
  2. Question about certain patch edits
    By cmrsf1 in forum General Questions
    Replies: 4
    Last Post: 27 Feb 2010, 12:35 AM
  3. XSS protection patch - and - PCI Scans - patch
    By janissaire in forum Templates, Stylesheets, Page Layout
    Replies: 3
    Last Post: 28 Jan 2010, 09:32 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR