Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

security bulletin - 3.3.0 up to 4.0.11

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #21  
Old 01-27-2005, 06:35 AM
 
DanUK DanUK is offline
 

X-Adept
  
Join Date: Dec 2003
Location: UK
Posts: 800
 

Default

Well that seems to work on my 3.5.4 now.

Dan
__________________
4.4.2

and

4.6.1
Reply With Quote
  #22  
Old 01-27-2005, 06:41 AM
 
funkydunk funkydunk is offline
 

X-Man
  
Join Date: Oct 2002
Location: Cambridge, UK
Posts: 2,210
 

Default

Quote:
Originally Posted by sstillwell@aerostich.com
In the alert the condition is specified as "Using IE"

So is this an IE flaw that we are patching xcart for or per se does it also affect someone using Firefox?

i got it with firefox
__________________
ex x-cart guru
Reply With Quote
  #23  
Old 01-27-2005, 09:20 AM
 
DanUK DanUK is offline
 

X-Adept
  
Join Date: Dec 2003
Location: UK
Posts: 800
 

Default

Hmmm, interesting.

If I now use the amended prepare.php (for 3.5.4) and then go to edit my categories and try to input some html in the description, it's stripping the html only leaving the plain text description when you click "submit". Reverts back to normal behaviour if I reinstate the old prepare.php. Anyone else find the same?

Thanks

Dan
__________________
4.4.2

and

4.6.1
Reply With Quote
  #24  
Old 02-01-2005, 05:35 PM
 
Genexx Genexx is offline
 

Newbie
  
Join Date: Mar 2004
Posts: 5
 

Default

Quote:
Originally Posted by DanUK
If I now use the amended prepare.php (for 3.5.4) and then go to edit my categories and try to input some html in the description, it's stripping the html only leaving the plain text description when you click "submit". Reverts back to normal behaviour if I reinstate the old prepare.php. Anyone else find the same?
Dan

I get the same thing, and also if I edit any text that has HTML in it, such as the welcome text.
Reply With Quote
  #25  
Old 02-01-2005, 10:58 PM
 
DanUK DanUK is offline
 

X-Adept
  
Join Date: Dec 2003
Location: UK
Posts: 800
 

Default

OK, I got a fix from X-Cart:

Code:
Please download X-Cart 3.5.14 distributions and open the 'admin/category_modify.php' file. Then copy the lines define('USE_TRUSTED_POST_VARIABLES',1); $trusted_post_variables = array("category_lng_description","category_new_description","description"); from the new version of the file to yours.

So, use the new prepare.php but add the lines above (taken from the top of a 3.5.14 category_modify.php) to your exisiting category_modify.php ...seems to do the trick

Dan
__________________
4.4.2

and

4.6.1
Reply With Quote
  #26  
Old 02-02-2005, 04:04 AM
  ETInteractive.com's Avatar 
ETInteractive.com ETInteractive.com is offline
 

X-Adept
  
Join Date: Dec 2002
Posts: 747
 

Default

so it this a fix for the FIX?

if so, Xcart should be sending out another news bulletin email with this.

RRF???
__________________
ETInteractive.com
X-Cart 3.5.x
Reply With Quote
  #27  
Old 02-02-2005, 04:53 AM
 
DanUK DanUK is offline
 

X-Adept
  
Join Date: Dec 2003
Location: UK
Posts: 800
 

Default

Well that would have been a fix if I hadn't discovered another similar bug in this file

When I submit changes on the templates, it's now stripping the html tags -half my admin menus ended up as plain text after trying to make an amendement! Another note to X-cart on its way.....

Dan
__________________
4.4.2

and

4.6.1
Reply With Quote
  #28  
Old 02-02-2005, 06:19 AM
  ETInteractive.com's Avatar 
ETInteractive.com ETInteractive.com is offline
 

X-Adept
  
Join Date: Dec 2002
Posts: 747
 

Default

keep us posted.

no one else is.

__________________
ETInteractive.com
X-Cart 3.5.x
Reply With Quote
  #29  
Old 02-02-2005, 11:36 PM
 
DanUK DanUK is offline
 

X-Adept
  
Join Date: Dec 2003
Location: UK
Posts: 800
 

Default

OK, I've had a response saying they're going to re-issue the patch (at least for 3.5.4) asap.

Dan
__________________
4.4.2

and

4.6.1
Reply With Quote
  #30  
Old 02-03-2005, 12:15 PM
  ETInteractive.com's Avatar 
ETInteractive.com ETInteractive.com is offline
 

X-Adept
  
Join Date: Dec 2002
Posts: 747
 

Default

2005?
__________________
ETInteractive.com
X-Cart 3.5.x
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 07:56 PM.

   

 
X-Cart forums © 2001-2020