Results 1 to 2 of 2

Security Risk

This is a discussion on Security Risk within the osCmax v1.7 Discussion forums, part of the osCmax v1.7 Forums category; I have been using credit class gv dc v5.05, I want to upgarde. There seems to be a security risk ...

      
  1. #1
    New Member
    Join Date
    Nov 2003
    Posts
    18
    Rep Power
    0


    Default Security Risk

    I have been using credit class gv dc v5.05, I want to upgarde.
    There seems to be a security risk I have noticed in this version v5.05, I wonder if this has been fixed in the updates.

    This is location of the updated version
    http://www.oscommerce.com/community/...h,Gift+Voucher

    The problem I found was concerning the incentive to open an account. Ie $10 gv

    I sign up for 3 account and then gave the vouchers to 4th ,

    the 4th account had $40 and was able to make a free purchase.

    I have not tested the discount, maybe this is ok?
    The % dc that is emailed is the same code everytime, does this apply to a new account only once?

    Another possable security risk, If someone generated a script to grap the $10 discount codes from a site, they could then use them on a bogus account to make free purchases. do you think this is possable? its a scary thought!
    Maybe they would use telnet or something, I have read there is some email risk with telnet but thats another story.
    I'm a newby and using max AABox.com MS2-MAX V1.5 version.
    I think credit class is great mod, but am scared of using it.
    I found a way to stop the email voucher incentive But does this fix all the risks

  2. #2
    Anonymous
    Guest


    Default

    Just an update on this. Some one said the email is sent twice, i dont thnk this is the case the 2 vouchers are sent in 1 email: hence 2 records logged in admin Vouchers/Coupons area

Similar Threads

  1. Security Issues..still?
    By adiwillow in forum osCMax v2 Features Discussion
    Replies: 3
    Last Post: 07-23-2006, 12:27 PM
  2. configure.php error = potential security risk
    By [wicked] in forum osCmax v2 Installation issues
    Replies: 3
    Last Post: 01-30-2006, 11:08 AM
  3. Security..
    By ph1ngering in forum osCommerce 2.2 Installation Help
    Replies: 0
    Last Post: 03-29-2005, 09:54 AM
  4. Admin Security
    By Keilup in forum osCMax v1.7 Installation
    Replies: 0
    Last Post: 10-27-2004, 07:05 AM
  5. includes/configure.php. Potential security risk
    By pirategnome in forum osCommerce 2.2 Installation Help
    Replies: 0
    Last Post: 12-10-2003, 02:46 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •