New Zenner
- Join Date:
- May 2008
- Posts:
- 52
- Plugin Contributions:
- 0
p4d Free Shipping Support
Hi
I am running
https://www.whiterose-equestrian.co.uk
Zen Cart 1.3.8a
Patch: 1::
Database Patch Level: 1.3.8
PHP Version 5.2.9
I have a number of contributions which do not affect the core code.
I have not experienced problems - but have been thinking and I am now concerned to the extent that I think I should ask for guidance
We use a third party shipping agent on occasion and find them very good. http://www.p4d.co.uk/
They offer a facility to download shipping info from ebay, oscommerce and zen. This comprises of the attached program that sits in the root directory
Looking at what it does, I am concerned that it could assist others to breach security. It doesn't sit behind an htaccess file. The password is freely available in that it sits in the file for all to see although this seems of limited value as it is supposed to correspond with the same password in the program that initiates the download in the p4d site.
I guess what is the core concern is that the code simply seems to ask for the server details from the config file and then use that information to download whatever. Using this principle any code could be implemented to access information.
Am I thinking correctly or are the checks in the system and I am way off beam
Any guidance on this would be gratefully recieved
Thank you