History
|
Log In
H
OME
B
ROWSE PROJECT
F
IND ISSUES
Q
UICK SEARCH:
Learn more about
Quick Search
Filter:
View
Edit
New
Manage
You are currently using a new, unsaved search.
Summary
Project:
osCommerce Core
Fix For:
2.2
Sorted by:
Priority ascending
Operations
Save
Issue Navigator
[
Permlink
]
Displaying issues
1
to
11
of
11
matching issues.
Current View:
Browser |
Printable
|
XML
| Full Content
(
HTML
|
Word
)
| Excel
(
All fields
|
Current fields
)
T
Key
Summary
Assignee
Reporter
Pr
Status
Res
Created
Updated
Due
OSC-1005
Possible error in V2.2 RC2
Mark Evans
Charles Dow
Closed
Won't Fix
03/Sep/09
07/Sep/09
OSC-1020
The osCommerce installation on the remote host has a supplementary script, 'extras/update.php', that fails to validate user-supplied input to the 'readme_file' parameter before using that to display a file.
Unassigned
Barbara King
Resolved
Fixed
17/Sep/09
19/Sep/09
OSC-761
Bypass of HTTP_GET_VARS escaping in osCommerce 2.2 RC2a with clean URLs enabled
Harald Ponce de Leon
WR
Closed
Fixed
12/Dec/08
12/Dec/08
OSC-762
Nearly arbitrary, remote code execution in osCommerce 2.2 RC2a on Windows with DNS e-mail verification enabled
Harald Ponce de Leon
WR
Closed
Fixed
12/Dec/08
12/Dec/08
OSC-763
Script injection due to outputting unescaped PHP_SELF
Harald Ponce de Leon
WR
Closed
Fixed
12/Dec/08
12/Dec/08
OSC-684
Information Disclosure
Harald Ponce de Leon
John Cobb
Closed
Fixed
06/Sep/08
12/Dec/08
OSC-963
Misspelled variable name in index.php: "cateqories_products"
Mark Evans
Sylvan
Resolved
Fixed
10/Jul/09
06/Sep/09
OSC-960
how to add zone number to ZONE RATE on shipping methods
Mark Evans
roland callanta
Resolved
Cannot Reproduce
08/Jul/09
06/Sep/09
OSC-999
Make osCommerce 2.2. PHP 5.3 Compatible
Mark Evans
Mark Evans
Reopened
UNRESOLVED
29/Aug/09
12/Oct/09
OSC-1008
Security problem: Inadequate validation of page name in admin section (higher priority)
Mark Evans
Jim Driscoll
Resolved
Fixed
03/Sep/09
05/Sep/09
OSC-907
CLONE -tep_session_is_registered() flaw with array_key_exists()
Harald Ponce de Leon
Gatis Linins
Open
UNRESOLVED
18/May/09
06/Sep/09