Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Security bulletin 2008-25-12

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #21  
Old 01-06-2009, 06:35 AM
  JWait's Avatar 
JWait JWait is offline
 

X-Man
  
Join Date: Nov 2005
Location: California
Posts: 2,440
 

Default Re: Security bulletin 2008-25-12

Quote:
Originally Posted by photo
There was only one file to update for version 4.1.10, prepare.php, so it was a pretty simple patch

I found something kind of strange in our 4.1.11 install. The original prepare.php was different, and the .DIFF wouldn't work. I opened the original prepare.php and the new one included with the security patch from 2008-25-12 and found they were very different, although both had the "# $Id: prepare.php,v 1.62.2.29 2008/08/07 11:25:02 joy Exp $" in the header.

Shouldn't at least the date be different?

There was a whole section missing on the original, from "define('X_REJECT_OVERRIDE', 1);" through (but not including) "if (!defined("XCART_EXT_ENV")) {" so needless to say I figured out why the patch wouldn't work.

I even checked with the original download from x-cart that I have on my computer and it just isn't there either.

Very strange.
__________________
Two Separate X-Cart Stores
Version 4.4.4 Gold - X-AOM - Vivid Dreams Aquamarine (modified) - Linux
Mods - Newest Products - View All -, and a few others. Numerous upgrades from 4.0.x series.
Integrated with Stone Edge Order Manager + POS

Version 4.1.12 Gold (fresh install) - X-AOM - Linux
Mods - XCSEO free
Reply With Quote
  #22  
Old 01-06-2009, 12:14 PM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Security bulletin 2008-25-12

Hi JWait -

You may want to subscribe to this thread - Beetlejuice reported the same thing with prepare.php and I have seen seen discrepancies between files within cart versions that should all have the same files. QT reports that if we updated correctly, we would have the same file versions in our distributions - they do not update files within a distribution release - so we all could have made the same mistake at some point on an upgrade with prepare.php. Beetlejuice submitted a help ticket and was going to report back in the above referenced thread.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #23  
Old 01-06-2009, 02:59 PM
  JWait's Avatar 
JWait JWait is offline
 

X-Man
  
Join Date: Nov 2005
Location: California
Posts: 2,440
 

Default Re: Security bulletin 2008-25-12

What Beetlejuice is reporting is similar what I found, except that our 4.1.11 site is not upgraded, yet the prepare.php on the site, and in the original download from x-cart is vastly different from the prepare.php included in the 2008-25-12 security patch. The strangest part is that the versions of the file are identical,

$Id: prepare.php,v 1.62.2.29 2008/08/07 11:25:02 joy Exp $
__________________
Two Separate X-Cart Stores
Version 4.4.4 Gold - X-AOM - Vivid Dreams Aquamarine (modified) - Linux
Mods - Newest Products - View All -, and a few others. Numerous upgrades from 4.0.x series.
Integrated with Stone Edge Order Manager + POS

Version 4.1.12 Gold (fresh install) - X-AOM - Linux
Mods - XCSEO free
Reply With Quote
  #24  
Old 01-07-2009, 10:32 AM
 
Belevation Belevation is offline
 

Member
  
Join Date: Dec 2008
Posts: 22
 

Unhappy Re: Security bulletin 2008-25-12

can someone tell me where the "File Area" in the HelpDesk is located?
__________________
4.1.5
Reply With Quote
  #25  
Old 01-07-2009, 11:25 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Security bulletin 2008-25-12

Hi JWait -

Yes - I do have discrepancies with file versions on a cart that was upgraded from 4.1.10 to 4.1.11 - not what you are reporting.

But - I also have a 4.1.11 cart that is not upgraded and I have been able to successfully add the 2008-12-18 and 2008-12-25 security patches. I can confirm that I do also see that the revision comment in the changed files is not updated. The files are changed, but the revision information remained the same. prepare.php remains 1.62.2.29 - it changed in both the 2008-12-18 and 2008-12-25 . I update manually, but the diff files look okay.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #26  
Old 01-07-2009, 11:36 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Security bulletin 2008-25-12

Hi Belevation -

When you log into your support helpdesk, the file area is the third item in the left vertical menu.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 09:16 AM.

   

 
X-Cart forums © 2001-2020