<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>ProductCart Shopping Cart Software Forums : Vulnerability? Able to change BTO price clientside</title>
  <link>https://forum.productcart.com/</link>
  <description><![CDATA[This is an XML content feed of; ProductCart Shopping Cart Software Forums : Using BTO : Vulnerability? Able to change BTO price clientside]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Fri, 10 Apr 2026 13:57:38 +0000</pubDate>
  <lastBuildDate>Wed, 18 Sep 2013 13:42:05 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forum.productcart.com/RSS_post_feed.asp?TID=5719</WebWizForums:feedURL>
  <image>
   <title><![CDATA[ProductCart Shopping Cart Software Forums]]></title>
   <url>https://forum.productcart.com/forum_images/pc_logo_50.png</url>
   <link>https://forum.productcart.com/</link>
  </image>
  <item>
   <title><![CDATA[Vulnerability? Able to change BTO price clientside : Hi Brett,Thank you for your comments....]]></title>
   <link>https://forum.productcart.com/vulnerability-able-to-change-bto-price-clientside_topic5719_post21606.html#21606</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=1">ProductCart</a><br /><strong>Subject:</strong> 5719<br /><strong>Posted:</strong> 18-September-2013 at 1:42pm<br /><br />Hi Brett,<div><br></div><div>Thank you for your comments. We agree and can assure you that we take security vulnerabilities and issues like this very seriously, and in fact had previously posted a patch for the same (or very similar) issue back under v4.1:</div><div><br></div><div><a href="http://www.productcart.com/release-log.asp" rel="nofollow">http://www.productcart.com/release-log.asp</a></div><div><br></div><div>However in terms of the current issue, it appears to be specific to IE10 only (at least in our tests) which is caching configuration pricing when the customer uses the browser's 'Back' button from the Shopping Cart Page (to go back to the Configuration Page). It would be very helpful to know if you are able to replicate this under other browsers as well?</div><div><br></div><div>At this time, we agree with your suggestion to remove the specifics of this vulnerability for security reasons and will contact you directly to verify the circumstances and post a full patch as soon as possible.</div><div><br></div><div>Sincerely,</div><div><br></div><span style="font-size:10px"><br /><br />Edited by earlyimp - 18-September-2013 at 1:42pm</span>]]>
   </description>
   <pubDate>Wed, 18 Sep 2013 13:42:05 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/vulnerability-able-to-change-bto-price-clientside_topic5719_post21606.html#21606</guid>
  </item> 
 </channel>
</rss>