View Issue Details

IDProjectCategoryView StatusLast Update
0005633OXID eShop (all versions)4.04. Securitypublic2015-03-12 16:45
Reportermarco_steinhaeuser Assigned To 
PrioritynormalSeverityfeatureReproducibilityalways
Status closedResolutionsuspended 
Product Version4.8.3 / 5.1.3 
Target Version4.8.5 / 5.1.5 
Summary0005633: replace allow_url_fopen by cURL
DescriptionIn OXID eShop, there are some methods to require allow_url_fopen in the PHP configuration of the server. In the shop itself it is actually not a problem because everything is escaped properly via quote() etc. but could become a security problem if modules were not coded properly.
Therefore, it is more appreciated, more smart and modern to use methods for cURL instead of allow_url_fopen.
Additional Informationhttp://forum.oxid-esales.com/showthread.php?t=22014
TagsNo tags attached.
ThemeBoth
BrowserAll
PHP Versionany
Database Versionany

Activities

svetlana

2014-03-28 10:04

reporter   ~0009745

waiting for the PO decision.

QA

2015-03-12 16:45

administrator   ~0010790

Last edited: 2015-03-18 10:06

moved to backlog