Any one can purchase Books, DVD and tees from your e-store without paying nothing. #38697

Closed
opened 2014-02-18 12:55:52 +01:00 by Bhaskar Borman · 13 comments

System Information
Operating system and graphics card

Windows 8, Radeon AMD

Blender Version
Broken: (example: 2.69.7 4b206af, see splash screen)
Worked: (optional)

Short description of error

Any one can purchase Books, DVD and tees from your e-store without paying nothing by simply modifying the http headers.

Exact steps for others to reproduce the error
Based on a (as simple as possible) attached .blend file with minimum amount of steps

**System Information** Operating system and graphics card Windows 8, Radeon AMD **Blender Version** Broken: (example: 2.69.7 4b206af, see splash screen) Worked: (optional) **Short description of error** Any one can purchase Books, DVD and tees from your e-store without paying nothing by simply modifying the http headers. **Exact steps for others to reproduce the error** Based on a (as simple as possible) attached .blend file with minimum amount of steps
Author

Changed status to: 'Open'

Changed status to: 'Open'
Author

Added subscriber: @root-3

Added subscriber: @root-3
Francesco Siddi was assigned by Sergey Sharybin 2014-02-18 15:21:02 +01:00

Added subscriber: @Sergey

Added subscriber: @Sergey

Hey there Bhaskar,
thanks for reporting the issue. We are checking on it, but we have additional backend checks, so that such orders don't actually get shipped.

Hey there Bhaskar, thanks for reporting the issue. We are checking on it, but we have additional backend checks, so that such orders don't actually get shipped.
Author

Hello Fsiddi,

Good to hear that you have backend checks but patch the vulnerability as soon as possible so that no one can take advantages on it. If you need any further help please let me know I would be very happy to help you.

Thank You.

Hello Fsiddi, Good to hear that you have backend checks but patch the vulnerability as soon as possible so that no one can take advantages on it. If you need any further help please let me know I would be very happy to help you. Thank You.

If you could mail me privately at francesco@blender.org it would be great.

If you could mail me privately at francesco@blender.org it would be great.

Changed status from 'Open' to: 'Archived'

Changed status from 'Open' to: 'Archived'

The issue is known and being taken care of.

The issue is known and being taken care of.

Added subscriber: @Blendify

Added subscriber: @Blendify

Changed status from 'Archived' to: 'Resolved'

Changed status from 'Archived' to: 'Resolved'

I assume this has been fixed

I assume this has been fixed

Changed status from 'Resolved' to: 'Archived'

Changed status from 'Resolved' to: 'Archived'

This is a known issue, we have backend checks to take care of it.

This is a known issue, we have backend checks to take care of it.
Sign in to join this conversation.
No Milestone
No project
No Assignees
4 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: infrastructure/blender-org#38697
No description provided.