Possible OpenCart Security Issue
59 posts
• Page 2 of 3 • 1, 2, 3
Re: Possible OpenCart Security Issue
wolfsteritory wrote:JAY6390 wrote:There's no reason you can't update the cache file, but it should be the data input that's sanitized IMO
what exactly do you mean by that ?
thank you
he means that the data should be sanitized as soon as you assign it to a variable in the zone file not after you've passed it off to two other files and gotten to the chache file.
OpenCart commercial mods and development http://spotonsolutions.net
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter
- Xsecrets
- Posts: 5042
- Joined: Sat Oct 24, 2009 7:51 pm
- Location: FL US
Re: Possible OpenCart Security Issue
So from reading this over time is it confirmed that the cache file should be updated?
Thanks
Chris
Thanks
Chris
Regards
Chris
Chris
- webpie it.
- Posts: 374
- Joined: Mon Jan 31, 2011 11:28 am
Re: Possible OpenCart Security Issue
webpie it. wrote:So from reading this over time is it confirmed that the cache file should be updated?
Thanks
Chris
well yes currently it is the only solution to the problem that has been provided. Though it really should not have to be changed, because you should never pass data to it that has not been sanitized, but at this point yes I would implement the fix if you have a live store.
OpenCart commercial mods and development http://spotonsolutions.net
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter
- Xsecrets
- Posts: 5042
- Joined: Sat Oct 24, 2009 7:51 pm
- Location: FL US
Re: Possible OpenCart Security Issue
webpie it. wrote:So from reading this over time is it confirmed that the cache file should be updated?
Thanks
Chris
Yes

Donate!|OpenCart Basics|GeoZones
Help me get more development cloud storage - Click Here to get DropBox
-

Qphoria - Administrator
- Posts: 18200
- Joined: Mon Jul 21, 2008 7:02 pm

Re: Possible OpenCart Security Issue
Can someone help me i have 3 stores thank you
- fealldagal
- Posts: 8
- Joined: Thu Oct 29, 2009 5:31 pm
Re: Possible OpenCart Security Issue
I am using 1491 and 1494
Thanks
Thanks
- fealldagal
- Posts: 8
- Joined: Thu Oct 29, 2009 5:31 pm
Re: Possible OpenCart Security Issue
fealldagal wrote:Can someone help me i have 3 stores thank you
You should just be able to download the file from the attachment in the first post, and FTP it into your hosting and overwrite the old file.
-

MattW - Posts: 63
- Joined: Sat Aug 28, 2010 3:37 am
- Location: Sheffield
Re: Possible OpenCart Security Issue
Thnaks MattW so just upload it and it should be find correct?
Thanks
Thanks
- fealldagal
- Posts: 8
- Joined: Thu Oct 29, 2009 5:31 pm
Re: Possible OpenCart Security Issue
fealldagal wrote:Thnaks MattW so just upload it and it should be find correct?
Thanks
Yep, that is all I've done on the 3 stores I support (all 1.4.9.6)
-

MattW - Posts: 63
- Joined: Sat Aug 28, 2010 3:37 am
- Location: Sheffield
Re: Possible OpenCart Security Issue
How insane would it be to put this important update on the OpenCart news feed? 

- FnF
- Posts: 79
- Joined: Sat Mar 19, 2011 1:59 pm
Re: Possible OpenCart Security Issue
FnF wrote:How insane would it be to put this important update on the OpenCart news feed?
Done

Donate!|OpenCart Basics|GeoZones
Help me get more development cloud storage - Click Here to get DropBox
-

Qphoria - Administrator
- Posts: 18200
- Joined: Mon Jul 21, 2008 7:02 pm

Re: Possible OpenCart Security Issue
its also php version related. not all version of php allow this hack.
php 5.3+ does not have this problem but 5.2.9 has.
php 5.3+ does not have this problem but 5.2.9 has.
OpenCart®
Project Owner & Developer.
OpenCart commercial support now available!
Project Owner & Developer.
OpenCart commercial support now available!
-

Daniel - Administrator
- Posts: 5173
- Joined: Fri Nov 03, 2006 10:57 am
Re: Possible OpenCart Security Issue
actually I'm running 5.3.6 and the hack somewhat works on it. You can create arbitrary files, but you cannot overwrite files because the %00 doesn't work.
OpenCart commercial mods and development http://spotonsolutions.net
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter
- Xsecrets
- Posts: 5042
- Joined: Sat Oct 24, 2009 7:51 pm
- Location: FL US
Re: Possible OpenCart Security Issue
Thanks for letting us know guys.
Can someone post the actual code change here because we modified this file already with the @touch($file); fixes to stop the cache error in the log files.
Kind Regards, Joan
Can someone post the actual code change here because we modified this file already with the @touch($file); fixes to stop the cache error in the log files.
Kind Regards, Joan
-

JoaniesGifts - Posts: 95
- Joined: Fri Oct 29, 2010 12:59 pm
- Location: UK
Re: Possible OpenCart Security Issue

Better Product SEO URL's - Perfectly structured product links
Better Category SEO URL's - Give subcategories the same SEO keyword
SEO URL's Route Editor - Fix all of your index.php links

-

JAY6390 - Posts: 4634
- Joined: Wed May 26, 2010 3:47 pm
- Location: United Kingdom
Re: Possible OpenCart Security Issue
xxxxxxxxxxx
Last edited by madlime on Thu Mar 29, 2012 2:21 pm, edited 1 time in total.
-

madlime - Posts: 22
- Joined: Sat May 28, 2011 9:56 am
- Location: Hong Kong
Re: Possible OpenCart Security Issue
madlime wrote:upload this file after not access admin panel ? user name and password not working
no. there is no possible way for that to happen with this file.

Donate!|OpenCart Basics|GeoZones
Help me get more development cloud storage - Click Here to get DropBox
-

Qphoria - Administrator
- Posts: 18200
- Joined: Mon Jul 21, 2008 7:02 pm

Re: Possible OpenCart Security Issue
xxxxxxxxxxxxxx
Last edited by madlime on Thu Mar 29, 2012 2:21 pm, edited 1 time in total.
-

madlime - Posts: 22
- Joined: Sat May 28, 2011 9:56 am
- Location: Hong Kong
59 posts
• Page 2 of 3 • 1, 2, 3
Return to News & Announcements
Who is online
Users browsing this forum: Cepreu, Google Feedfetcher, Wade C and 13 guests














