02-28-2012, 07:00 PM
After bumping my head against the wall I finally figured that this is the problem with Fancybox.

You want to protect the image directory from intrusion with other file types, but this Add-On is incorrect. Use the new .htaccess files/text in the .htaccess files of the image directories, both admin and catalog.

http://www.oscommerce.info/confluence/display/OSCOM23/%28AC%29+%28UP%29+Add+htaccess+Protection+to+the+I mages+Directory

This link leads to a v2.3.0 documentation but should be solid to v2.2, etc.

The code is posted here for convenience:

# $Id$
# This is used to restrict access to this folder to anything other
# than images

# Prevents any script files from being accessed from the images folder

Order Deny,Allow
Deny from all

