Welcome, Guest ( Customer Panel | Login )




 All Forums
 VPCart Forum
 Problems and bugs
 Saved Cart''s and Wishlist
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

fecal_storm
Starting Member

14 Posts

Posted - April 02 2005 :  21:16:42  Show Profile  Reply with Quote
Not sure if this happens with saved carts, but I recently saved a cart with a small quote in the name "Zach's Cart" and it causes a SQL fail error if you attempt to restore or delete because the quote is not escaped. I was able to escape the quote in the actual URL string and get the cart deleted, but it would not be so easy for a non developer to figure out what was wrong.

greatphoto
VP-CART Super User

USA
304 Posts

Posted - April 03 2005 :  00:23:05  Show Profile  Reply with Quote
Could this be used as a SQL injection vulnerability?

Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Snitz Forums 2000
0 Item(s)
$0.00