Issue #18: December 23, 2002
By Harald Ponce de Leon
December 23, 2002
New Team Member
Security Issue For Demonstration Showcases
New Workboard Section
Contributions Section Updated
New Friendlier URLs
Seasons Greetings
New Team Member
Matthijs vd Vegte, who was recently assigned Godly status, has joined the project team for his continuous efforts in the forums of helping out the community.
Welcome aboard Matthijs!
Matthijs has been the second person posting already over 1000 messages in the forums, with Linda still leading.
Security Issue For Demonstration Showcases
Peter Beernink recently informed the community of a possible security issue mainly affecting demonstration showcases of the Administration Tool.
It is possible to upload PHP files as new product images which are parsed when previewing the product and everytime the product is viewed on the Catalog.
Damage is possible depending on the contents of the PHP file.
Security is planned for the file upload class to deny or accept file uploads based on their extension.
The posting can be read on the forums at:
https://www.oscommerce.com/forums/viewtopic.php?t=29346
New Workboard Section
The Workboard section, which replaces the Current Tasks section, shows what features are assigned to which Milestone release as described in the previous Weekly Summary report.
As development has been slow this month due to the festive season, we are looking at finalizing the first Milestone release in January.
The Workboard section can be reached at:
https://www.oscommerce.com/community/workboard
Contributions Section Updated
The Contributions section has been updated and now offers an easy to use navigation method.
Contributions with multiple releases have been sorted into single packages which not only provides easy access to related files, but allows the community to keep up to date on their favourite contributions.
The new section is still under maintenance due to the amount of contributions to sort through - thanks go to Jan and Ian for helping out in the process.
The new Contributions section has been moved to the Community area of the support site, and can be reached at:
https://www.oscommerce.com/community/contributions
New Friendlier URLs
The URLs on the support site have been updated to provide more friendlier links.
The ".php" extension has been dropped allowing for links such as:
https://www.oscommerce.com/community.php/bugs
to be called as:
https://www.oscommerce.com/community/bugs
Seasons Greetings
On behalf of the development team and community, we wish all a Merry Christmas and great festive season, and look forward to what the new year brings.