Zen Follower
- Join Date:
- Jul 2005
- Location:
- Orlando, Fl
- Posts:
- 343
- Plugin Contributions:
- 0
Internal Server Error - Updating Products
When I try to update some of my products I receive an Internal Server Error once I hit preview.
zencart 1.3.8a php5
Views: 1,667
Zen Follower
When I try to update some of my products I receive an Internal Server Error once I hit preview.
zencart 1.3.8a php5
Zen Follower
Ok, upon further invesagation, I have isolated it to this:
Any products that contain "http://" in the description will result in an Internal Service Error upon clicking the preview button.
If I take away the "http://" they will update normally.
How do I fix this error ?
Thanks
DD
Sensei
http://www.zen-cart.com/forum/showthread.php?t=70792&highlight=mod_security
http://www.zen-cart.com/forum/showthread.php?t=73758&highlight=mod_security
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Zen Follower
I tried adding this code to my .htaccess file in my admin directory:
<IfModule mod_security.c> SecFilterEngine Off SecFilterScanPOST Off </IfModule>I am still getting the Internal Service Error.
Thanks
Sensei
Then you'll need to look at your server's errorlogs for the cause.
Or ask your host to help you, since they're the ones setting up the rules for what is allowed and not allowed.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Zen Follower
This is what they found:
ModSecurity: Access denied with code 500 (phase 2). Pattern match "(ht|f)tps?:/" at ARGS:products_description[1]. [hostname "www.mydomain.com"] [uri "/admin/product.php?cPath=1_3&product_type=1&pID=107&action=new_product_preview&page=1"] [unique_id "hW5lqUMrAA4AABhSFYMAAAAF"]
Sensei
Right ... that means they've got a rule set up to deny the use of "http:/" and "ftp:/" in any form that gets submitted on the server.
You have 4 options:
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Zen Follower
Are you saying that there might even be a rule that doesnot allow me to use my htaccess files also ?
This is how my admin htacess looks :
<IfModule mod_security.c> SecFilterEngine Off SecFilterScanPOST Off </IfModule>#<IfModule mod_php4.c>
#</IfModule>
Is this correct ?
Thanks
Sensei
djdavedawson:
Are you saying that there might even be a rule that doesnot allow me to use my htaccess files also ?
Yes, that is true ... and only your hosting company can allow you to override that.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Zen Follower
Thanks for the help. My web host was able to turn that off for me.
DD
Tell staff why this post should be reviewed.