Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[KIS-2014-08] OpenCart PHP Object Injection Vulnerability #1667

Closed
wookiecooking opened this issue Jul 30, 2014 · 2 comments
Closed

[KIS-2014-08] OpenCart PHP Object Injection Vulnerability #1667

wookiecooking opened this issue Jul 30, 2014 · 2 comments

Comments

@wookiecooking
Copy link

http://seclists.org/bugtraq/2014/Jul/64

@jamesallsup
Copy link
Contributor

This has already been patched on 1.5.6.x and master branches.

@danielkerr
Copy link
Member

This is a bug not a vulnerability. what's reported here has been completely untested as "DBMySQLi“ requires a connection to be initialised. As for the XML External Entity (XXE) attacks well the person who reported this issue is to stupid to realise the same filters that block html being sent in customer inputs would also filter xml being used.

its amazing that low life's such as (Egidio Romano) manage to pass them self s off as security professionals.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants