<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: SimpleCart JS &#8211; Easy eCommerce Solution</title> <atom:link href="http://churchcrunch.com/simplecart-js-easy-ecommerce-solution/feed/" rel="self" type="application/rss+xml" /><link>http://churchcrunch.com/simplecart-js-easy-ecommerce-solution/</link> <description>Exploring the Intersection of Web Technology and the Church</description> <lastBuildDate>Wed, 17 Mar 2010 19:55:11 +0000</lastBuildDate> <generator>http://wordpress.org/?v=2.9.2</generator> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: Ben Dyer</title><link>http://churchcrunch.com/simplecart-js-easy-ecommerce-solution/comment-page-1/#comment-50267</link> <dc:creator>Ben Dyer</dc:creator> <pubDate>Mon, 09 Nov 2009 16:43:17 +0000</pubDate> <guid
isPermaLink="false">http://churchcrunch.com/?p=6967#comment-50267</guid> <description>Hm. All JavaScript? Just as an experiment, I used Firebug to modify the HTML source and sure enough, that $22.99 copy of Wolverine was passed to PayPal for $0.01.
Sure, you don&#039;t have to fulfill the order, I guess, but that&#039;s a pretty sizable security hole. That&#039;s the benefit of DB-based shopping carts, you have a database to check against to prevent things like this.
Yeah, probably not an issue for smaller organizations, but they also likely won&#039;t even know that this could potentially be an issue. </description> <content:encoded><![CDATA[<p>Hm. All JavaScript? Just as an experiment, I used Firebug to modify the HTML source and sure enough, that $22.99 copy of Wolverine was passed to PayPal for $0.01.</p><p>Sure, you don&#039;t have to fulfill the order, I guess, but that&#039;s a pretty sizable security hole. That&#039;s the benefit of DB-based shopping carts, you have a database to check against to prevent things like this.</p><p>Yeah, probably not an issue for smaller organizations, but they also likely won&#039;t even know that this could potentially be an issue.</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Served from: churchcrunch.com @ 2010-03-17 16:32:44 by W3 Total Cache -->