Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls

Error 406 - Not Acceptable
 
Reply
   X-Cart forums > Considering X-Cart > Considering using X-Cart for my project
 
Thread Tools Search this Thread
  #1  
Old 12-06-2012, 04:30 PM
 
Dmitri Z Dmitri Z is offline
 

Member
  
Join Date: Feb 2012
Posts: 10
 

Default Error 406 - Not Acceptable

HI,

I just installed X-cart gold on my hosting, and after playing with it for 5 minutes I got error

"Error 406 - Not Acceptable

An error has occurred. Generally a 406 error is caused because a request has been blocked by Mod Security. If you believe that your request has been blocked by mistake please contact the web site owner."

Could you help me to resolve and avoid this problem in future?

Thank You,
Dmitri
__________________
X-Cart Gold v4.4.5
Reply With Quote
  #2  
Old 12-06-2012, 08:34 PM
 
UHS UHS is offline
 

Advanced Member
  
Join Date: Nov 2010
Posts: 32
 

Default Re: Error 406 - Not Acceptable

Mod Security is a module installed on your hosting server. Best to work with your website host to resolve the issue.
__________________
Jonathon Prevost
Upper Hand Technologies

http://www.upperhandtech.com/
Reply With Quote

The following user thanks UHS for this useful post:
ambal (12-06-2012)
  #3  
Old 12-07-2012, 02:33 PM
 
Dmitri Z Dmitri Z is offline
 

Member
  
Join Date: Feb 2012
Posts: 10
 

Default Re: Error 406 - Not Acceptable

Hi,

My hosting support told me that they can disable mod security if I need. Do you think I need to disable mod security? I can't find this info in server requirements. I have this error happened in my Safari browser, but in other browsers X-cart was working fine.

Thank You,
Dmitri
__________________
X-Cart Gold v4.4.5
Reply With Quote
  #4  
Old 12-07-2012, 02:49 PM
 
Thomasb134 Thomasb134 is online now
 

X-Adept
  
Join Date: Apr 2007
Location: USA
Posts: 756
 

Default Re: Error 406 - Not Acceptable

There's a lot of similar cases involving mod security and the 406 error. Here's an example, one of many:
http://tech.shantanugoel.com/2008/05/01/http-406-errors-galore.html

Quote:
My hosting support told me that they can disable mod security if I need.
Rather than disabling mod security it would be much better to work with the website host and have them fine tune their mod security rules.

Quote:
Do you think I need to disable mod security?
You need every bit of protection you can get. Disabling it just opens another crack to the hackers.
__________________
Thomas / USA
XCart V4.4.5 Gold
XCart Mobile V1.4.12
XCart X-PDF
XCart X-HotProducts
AlteredCart Checkout One (One Page Checkout)
BCSE Back In Stock
CFL Holiday Message
CFL System Message
Smack Digital (WebsiteCM) Remember Anon Carts
xcartmods Testimonials
Unix, PHP 7.0 (patched 5.4). Currently patching PHP 7.1
MySQL 5.6
Reply With Quote

The following user thanks Thomasb134 for this useful post:
ambal (12-10-2012)
  #5  
Old 03-21-2013, 11:37 AM
 
MikeDelic MikeDelic is offline
 

Newbie
  
Join Date: Mar 2013
Posts: 1
 

Default Re: Error 406 - Not Acceptable

Actually, changing the rules is the world upside-down. The default Mod Security rules are there for a reason. The particular rules is triggered by a "invalid" value set inside a cookie which is generated by X-Cart. In my opinion X-Cart should adjust their code to fulfill the rules.

In our case the rule was triggered by setting up a payment method:
Code:
/admin/cc_processing.php?mode=add&subscribe=&payment_country=ALL&processor=cc_[any_payment_type].php HTTP/1.1

Below the actual triggered result:
Code:
Access denied with code 406 (phase 2). Pattern match "\\b(\\d+) ?=?\\1\\b|[\\'\"](\\w+)[\\'\"] ?= ?[\\'\"]\\2\\b" at REQUEST_HEADERS:Cookie. file "/usr/local/apache/conf/modsec2.user.conf"] [line "98"] [id "1234123413"] [msg "SQL Injection Attack"] [data "1=1"] [severity "CRITICAL"] [tag "WEB_ATTACK/SQL_INJECTION"]

As you put it so nicely "You need every bit of protection you can get". Changing the rules means creating security holes and that is exactly what you shouldn't do.
__________________
Hostmaster
Several X-Cart versions
Reply With Quote
  #6  
Old 02-25-2016, 05:34 AM
 
Paul H . Paul H . is offline
 

Advanced Member
  
Join Date: Mar 2012
Posts: 58
 

Default Re: Error 406 - Not Acceptable

I just started getting this 406 error when I try to change the skin or languages
Is this definately down to the host to sort out ?
Also maybe unrelated but sometimes when editing products I constantly get logged out ?
__________________
Gold 4.7.5-Ideal Responsive
Reply With Quote
  #7  
Old 02-25-2016, 08:53 AM
 
Paul H Paul H is offline
 

eXpert
  
Join Date: Sep 2005
Posts: 242
 

Default Re: Error 406 - Not Acceptable

I got in touch with my host and they just turned off mod security there was no other option
__________________
Xcart Gold 4.1.11-Gone
= 4.4.5-Live
Reply With Quote
Reply
   X-Cart forums > Considering X-Cart > Considering using X-Cart for my project


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 06:42 AM.

   

 
X-Cart forums © 2001-2018