In Topic: PHP 5.2.5 and Prior Versions Multiple Vulnerabilities

14 August 2008 - 12:54 PM

Version 5.2.6
Security Fixes
Fixed possible stack buffer overflow in FastCGI SAPI. (Andrei Nigmatulin)
Properly address incomplete multibyte chars inside escapeshellcmd() (Ilia, Stefan Esser)
Fixed security issue detailed in CVE-2008-0599. (Rasmus)
Fixed a safe_mode bypass in cURL identified by Maksymilian Arciemowicz. (Ilia)
Upgraded PCRE to version 7.6 (Nuno)

In Topic: Help Me Prevent being scammed - first international orders

29 July 2008 - 11:29 PM

If your in doubt either make verbal contact with customer or require a check. I actually have just shut off all CC processing outside of US and Canada and require customers to send checks for International. And only after the check is cleared and funds safely in my bank account do I process the order.

In the US I also highly recommend using AVS and CVV checking. If either fails contact the customer over the phone for verbal confirmation. Just emailing someone doesn't mean jack these days with free email accounts.

In Topic: ??HELP Cscart sending invoices out

29 July 2008 - 11:09 PM

I am testing and setting up my cart. But I too am getting customer emails for declined orders where the "Notify customer" is not checked. However "Notify supplier" is checked and I am not unchecking that but why would that send an email to the customer?

In Topic: New Payment method, help required

29 July 2008 - 10:18 AM

Because it is not reading any of your code with:

if (!defined('IN_CSCART')) {

That means don't do this if IN_CSCART is defined,which it is (i would imagine).