osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 
 

Security Risk

This is a discussion on Security Risk within the osCMax v1.7 Discussion forums, part of the osCMax v1.7 Forums category; I have been using credit class gv dc v5.05, I want to upgarde. There seems to be a security risk ...


Go Back   osCommerce and osCMax shopping cart software forums > osCMax v1.7 Forums > osCMax v1.7 Discussion

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 03-25-2004, 08:07 AM
New Member
 
Join Date: Nov 2003
Posts: 18
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
AceDog
Default Security Risk

I have been using credit class gv dc v5.05, I want to upgarde.
There seems to be a security risk I have noticed in this version v5.05, I wonder if this has been fixed in the updates.

This is location of the updated version
http://www.oscommerce.com/community/...h,Gift+Voucher

The problem I found was concerning the incentive to open an account. Ie $10 gv

I sign up for 3 account and then gave the vouchers to 4th ,

the 4th account had $40 and was able to make a free purchase.

I have not tested the discount, maybe this is ok?
The % dc that is emailed is the same code everytime, does this apply to a new account only once?

Another possable security risk, If someone generated a script to grap the $10 discount codes from a site, they could then use them on a bogus account to make free purchases. do you think this is possable? its a scary thought!
Maybe they would use telnet or something, I have read there is some email risk with telnet but thats another story.
I'm a newby and using max AABox.com MS2-MAX V1.5 version.
I think credit class is great mod, but am scared of using it.
I found a way to stop the email voucher incentive But does this fix all the risks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #2  
Old 03-26-2004, 03:13 AM
Anonymous
Guest
 
Posts: n/a
Default

Just an update on this. Some one said the email is sent twice, i dont thnk this is the case the 2 vouchers are sent in 1 email: hence 2 records logged in admin Vouchers/Coupons area
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
Security Issues..still? adiwillow osCMax v2 Features Discussion 3 07-23-2006 12:27 PM
configure.php error = potential security risk [wicked] osCMax v2 Installation issues 3 01-30-2006 11:08 AM
Security.. ph1ngering osCommerce 2.2 Installation Help 0 03-29-2005 09:54 AM
Admin Security Keilup osCMax v1.7 Installation 0 10-27-2004 07:05 AM
includes/configure.php. Potential security risk pirategnome osCommerce 2.2 Installation Help 0 12-10-2003 02:46 PM


All times are GMT -8. The time now is 04:59 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax