Zen Cart Logo
Forums / Bug Reports / [Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

[Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

Locked

Views: 2,038

Results 1 to 6 of 6
This thread is locked. New replies are disabled.
6 Jul 2007, 8:00 PM
#1
wlamoreaux avatar

wlamoreaux

New Zenner

Join Date:
Jul 2007
Posts:
42
Plugin Contributions:
0

[Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

if anyone has a fix for this please let me know but, I have done alot of testing to make sure that i did "find" this error and have it narrowed down to what it is.

I have a Product called

-O'Keeffe's Working Hands

and the Products Manufacturer is

-O'Keeffe's

I only have one payment option inabled and that's
authorize.net (aim)

if you have a quote in the product name it will error out your checkout on the final step.

but if you take the sigle quote out of the name it works just fine.

the error i get is

1064 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'Keeffe's Working Hands(qty: 1) [Date] => July 6, 2007, 2:52 pm [IP] => ' at line 1
in:
[insert into zen_authorizenet (id, customer_id,order_id, response_code, response_text, authorization_type, transaction_id, sent, received, time, session_id) values ('', '1', '1', '3', '(TESTMODE) The merchant login ID or password is invalid or the account is inactive.', 'auth_capture', '0', 'Array ( [x_login] => ******* [x_tran_key] => ******* [x_relay_response] => FALSE [x_delim_data] => TRUE [x_version] => 3.1 [x_type] => AUTH_CAPTURE [x_method] => CC [x_amount] => 17.33 [x_card_num] => *******0015 [x_exp_date] => 0109 [x_card_code] => ******* [x_email_customer] => FALSE [x_email_merchant] => FALSE [x_cust_id] => 1 [x_invoice_num] => TEST-1 [x_first_name] => William [x_last_name] => Lamoreaux [x_company] => [x_address] => 1500 Preston Rd [x_city] => Dallas [x_state] => Texas [x_zip] => 75093 [x_country] => United States [x_phone] => 469-212-4850 [x_email] => [email protected] [x_ship_to_first_name] => William [x_ship_to_last_name] => Lamoreaux [x_ship_to_address] => 1500 Preston Rd [x_ship_to_city] => Dallas [x_ship_to_state] => Texas [x_ship_to_zip] => 75093 [x_ship_to_country] => United States [x_description] => O'Keeffe's Working Hands(qty: 1) [Date] => July 6, 2007, 2:52 pm [IP] => 71.123.143.121 [Session] => 0ae8875fe62a244c35dc3021f57ed2db [x_test_request] => TRUE [url] => https://secure.authorize.net/gateway/transact.dll ) ', '1=3&2=2&3=13&4=%28TESTMODE%29+The+merchant+login+ID+or+password+is+invalid+or+the+account+is+inactive.&5=000000&6=P&7=0&8=&9=&10=17.33&11=&12=auth_capture&13=&14=&15=&16=&17=&18=&19=&20=&21=&22=&23=&24=&25=&26=&27=&28=&29=&30=&31=&32=&33=&34=&35=&36=&37=&38=9F7D8E6783D5B5C8D3989A95DA9AF5AF&39=&40=&41=&42=&43=&44=&45=&46=&47=&48=&49=&50=&51=&52=&53=&54=&55=&56=&57=&58=&59=&60=&61=&62=&63=&64=&65=&66=&67=&68=&69=July+6+2007+2%3A52+pm&70=71.123.143.121&71=0ae8875fe62a244c35dc3021f57ed2db', 'July 6, 2007, 2:52 pm', '0ae8875fe62a244c35dc3021f57ed2db')]

6 Jul 2007, 8:05 PM
#2
wlamoreaux avatar

wlamoreaux

New Zenner

Join Date:
Jul 2007
Posts:
42
Plugin Contributions:
0

Re: [Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

wlamoreaux:

if anyone has a fix for this please let me know but, I have done alot of testing to make sure that i did "find" this error and have it narrowed down to what it is.

I have a Product called

-O'Keeffe's Working Hands

and the Products Manufacturer is

-O'Keeffe's

I only have one payment option inabled and that's
authorize.net (aim)

if you have a quote in the product name it will error out your checkout on the final step.

but if you take the sigle quote out of the name it works just fine.

the error i get is

1064 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'Keeffe's Working Hands(qty: 1) [Date] => July 6, 2007, 2:52 pm [IP] => ' at line 1
in:
[insert into zen_authorizenet (id, customer_id,order_id, response_code, response_text, authorization_type, transaction_id, sent, received, time, session_id) values ('', '1', '1', '3', '(TESTMODE) The merchant login ID or password is invalid or the account is inactive.', 'auth_capture', '0', 'Array ( [x_login] => ******* [x_tran_key] => ******* [x_relay_response] => FALSE [x_delim_data] => TRUE [x_version] => 3.1 [x_type] => AUTH_CAPTURE [x_method] => CC [x_amount] => 17.33 [x_card_num] => *******0015 [x_exp_date] => 0109 [x_card_code] => ******* [x_email_customer] => FALSE [x_email_merchant] => FALSE [x_cust_id] => 1 [x_invoice_num] => TEST-1 [x_first_name] => William [x_last_name] => Lamoreaux [x_company] => [x_address] => 1500 Preston Rd [x_city] => Dallas [x_state] => Texas [x_zip] => 75093 [x_country] => United States [x_phone] => 469-212-4850 [x_email] => [email protected] [x_ship_to_first_name] => William [x_ship_to_last_name] => Lamoreaux [x_ship_to_address] => 1500 Preston Rd [x_ship_to_city] => Dallas [x_ship_to_state] => Texas [x_ship_to_zip] => 75093 [x_ship_to_country] => United States [x_description] => O'Keeffe's Working Hands(qty: 1) [Date] => July 6, 2007, 2:52 pm [IP] => 71.123.143.121 [Session] => 0ae8875fe62a244c35dc3021f57ed2db [x_test_request] => TRUE [url] => https://secure.authorize.net/gateway/transact.dll ) ', '1=3&2=2&3=13&4=%28TESTMODE%29+The+merchant+login+ID+or+password+is+invalid+or+the+account+is+inactive.&5=000000&6=P&7=0&8=&9=&10=17.33&11=&12=auth_capture&13=&14=&15=&16=&17=&18=&19=&20=&21=&22=&23=&24=&25=&26=&27=&28=&29=&30=&31=&32=&33=&34=&35=&36=&37=&38=9F7D8E6783D5B5C8D3989A95DA9AF5AF&39=&40=&41=&42=&43=&44=&45=&46=&47=&48=&49=&50=&51=&52=&53=&54=&55=&56=&57=&58=&59=&60=&61=&62=&63=&64=&65=&66=&67=&68=&69=July+6+2007+2%3A52+pm&70=71.123.143.121&71=0ae8875fe62a244c35dc3021f57ed2db', 'July 6, 2007, 2:52 pm', '0ae8875fe62a244c35dc3021f57ed2db')]

i have also replaced the single quote with a ` i don't know what it is called but it's a backwards appostirfie and it worked just fine. so this seems to be a problem on createing the product in the admin.

Please if anyone has a fix for this please let me know cause alot of my products have special char's like this.

6 Jul 2007, 8:12 PM
#3
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

What version of Zen Cart?
Are you using the auth.net AIM module that came "with" Zen Cart, or have you patched it in any way?
What version of MySQL ?

7 Jul 2007, 7:51 AM
#4
wlamoreaux avatar

wlamoreaux

New Zenner

Join Date:
Jul 2007
Posts:
42
Plugin Contributions:
0

Re: [Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

DrByte:

What version of Zen Cart?
Are you using the auth.net AIM module that came "with" Zen Cart, or have you patched it in any way?
What version of MySQL ?

ahh sorry i didn't include that info, my bad.....

nothing is modded that would affect this. my shipping and payment is not modded at all.

Zen Cart 1.3.7
Database Patch Level: 1.3.7
v1.3.7 [2007-07-05 23:35:20] (Fresh Installation)

**Server OS: **Linux 2.6.9-55.ELsmp
**PHP Version: **4.4.7 (Zend: 1.3.0)
**Database: **MySQL 4.1.21-standard
**HTTP Server: **Apache/1.3.37

also just to test i uploaded a "fresh" copy of zen to a test account i have on this server and just added on catagory and on product and tested with authorize (aim) and had same error.

so on that fresh install i just removed the single quote from the product name and it worked just fine.

But as for my customer she's not going to "remember" not to use single quotes so i am hopeing that there is some type of fix for this.

Thanks

7 Jul 2007, 8:20 AM
#5
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: [Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

Is it any different using this updated version of the module?

http://www.zen-cart.com/forum/showpost.php?p=310464&postcount=45

NOTE: the problem has been fixed in v1.3.8

2 Feb 2009, 3:57 PM
#6
gonsman avatar

gonsman

New Zenner

Join Date:
Oct 2005
Posts:
35
Plugin Contributions:
1

Re: [Done v1.3.8] Single Quote Problem Durning Checkout - AIM module

I had this problem also and I believe that I have fixed it. The SQL insert needs to be backslashed so the database does not think the column data has ended and a new column has started. This happens using a single quote. On line 463 of the file includes/modules/payment/authorizenet_aim.php there is the following line:

$db->Execute("insert into " . TABLE_AUTHORIZENET . "  (id, customer_id,order_id, response_code, response_text, authorization_type, transaction_id, sent, received, time, session_id) values ('', '" . $_SESSION['customer_id'] . "', '" . $new_order_id . "', '" . $db_response_code . "', '" . $db_response_text . "', '" . $db_authorization_type . "', '" . $db_transaction_id . "', '" . print_r($reportable_submit_data, true) . "', '" . $response_list . "', '" . $order_time . "', '" . $db_session_id . "')");

I change it to:

$db->Execute("insert into " . TABLE_AUTHORIZENET . "  (id, customer_id,order_id, response_code, response_text, authorization_type, transaction_id, sent, received, time, session_id) values ('', '" . $_SESSION['customer_id'] . "', '" . $new_order_id . "', '" . $db_response_code . "', '" . $db_response_text . "', '" . $db_authorization_type . "', '" . $db_transaction_id . "', '" . addslashes(print_r($reportable_submit_data, true)) . "', '" . $response_list . "', '" . $order_time . "', '" . $db_session_id . "')");