in reply to Re: perl shopping cart
in thread perl shopping cart
Have you never seen a shopping cart that lets the user change prices by submitting hidden form fields?
Have you never seen a shopping cart that is vulnerable to SQL injection attacks?
Have you never seen a shopping cart that stores your current location on the server and therefore doesn't let you navigate through two parts of the site in parallel (for comparison shopping purposes)?
How about ones that let you store user comments - and were then vulnerable to cross-site scripting attacks?
Or have you seen shopping carts that made any or all of these mistakes but you didn't know enough to realize it? Which is more likely?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: perl shopping cart
by gothic_mallard (Pilgrim) on Oct 26, 2004 at 17:01 UTC | |
by tilly (Archbishop) on Oct 26, 2004 at 18:31 UTC | |
by gothic_mallard (Pilgrim) on Oct 27, 2004 at 06:41 UTC |