allcommerce-newbies Mailing List for AllCommerce - ecommerce and fulfilment
Brought to you by:
lee_herron
You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
(17) |
May
|
Jun
(12) |
Jul
(14) |
Aug
(6) |
Sep
(7) |
Oct
|
Nov
(1) |
Dec
(1) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(3) |
Oct
|
Nov
|
Dec
|
| 2004 |
Jan
|
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2006 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(1) |
|
From: Cary B. <car...@ho...> - 2006-12-07 14:02:51
|
BEWARE!! A piece of friendly advice for anyone thinking of using this program... This is one of the most cumbersome applications I have ever had the opportunity to evaluate. IF (and that's a big IF) you can manage to get it installed, the manner in which this app requires you to specifiy the site layout and enter product info is SO UNBELIEVABLY CUMBERSOME compared to other applications, you would be better off saving a few hairs on your head and going with something else. I would suggest LiteCommerce (www.litecommerce.com). The price of this app is right (under $100 for the base version), and setup is easy. I am not affiliated with the LiteCommerce app in any way, but it is the application I decided to go with. Just as an example of how awful AllCommerce is to install, I needed to edit the php script that creates mysql tables in the specified database, because the script had syntax errors resulting in specific tables not being created under the latest version of mysql. For example, many "create table" statements had an empty string default value specified for an INT column (which generated silent errors that you didn't know about until later), or had default empty string values specified for AUTOINCREMENT INT columns (again, silent errors), resulting in problems (the program wouldn't run correctly).. And IF you manage to get it installed, you'll be running for the hills in no time when you try to make it work. Scary.... CB _________________________________________________________________ Get the latest Windows Live Messenger 8.1 Beta version. Join now. http://ideas.live.com |
|
From: Jamey L. <ja...@th...> - 2004-02-25 19:17:26
|
Hi all, just downloaded and installed today! The install went well, everything is up and running from what I can tell. When I go to the admin section and try to login I get the following error: You need cookies to use admin. I check my browser (IE6) just to be sure I didn't have cookies turned off for some reason, and the setting are fine. When I look in my apache error log I found this: DBI::db=HASH(0x832ec90)->disconnect invalidates 1 active statement handle (either destroy statement handles or call finish on them before disconnecting) at /usr/local/www/cgi-bin/om/admin/login.cgi line 334. Can anyone help me figure out what's going on, or what this error message means? Apache-1.3.29_1 mysql-server-4.0.16 p5-DBI-1.38 p5-DBD-mysql-2.9003 p5-libwww-5.75 Thanks, Jamey |
|
From: Peter D. <mer...@ma...> - 2002-09-17 23:51:13
|
Its nice to hear that this project going to be alive again. I would like to have Posgresql backend, Plug in accounting package SQL-Ledger, CRM with connection to LDAP and futher develop WMS I'm curently maintaining Polish translation for SQL-Ledger, and planing to translate Allcommerce into polish. Unfortunately I haven't got any programing skills. Good Luck Peter Dabrowski ----- Original Message ----- From: Barry <gld...@ac...> Date: Tue, 17 Sep 2002 03:59:41 -0700 To: all...@li... Subject: [Allcommerce-newbies] Notice - new guy on the team > I'm the new guy on the team. > > I joined in response to lee heron's posting for someone to take over the > project and find the means to keep it alive, as admin and Project Lead. > I have been requested to poll the responses that I receive from this > post in order to determine a direction to take the project. First let me > say that "I believe in this product" or I wouldn't be jumping onto an > otherwise sunken ship. I dare say that all who have successfully > implemented AllCommerce, believe in it too. > > But all of that to say this... > > I need a consensus of opinion of this project from those who are still > interested in being involved with it's further development, directly, > not just standing by if you get my meaning. > > Then I need to have all who are on this team post their skills profile > and make it publicly available, so I can get a feel for who can do what. > > I also have adapted a version of the last download version of > AllCommerce to RedHat Linux 7.3 and when I am satisfied that I have > tested it sufficiently, I will make it available for download as "beta" > and with a new name if we have to, just to get it back into the public > eye. > > Lee Heron advised me that he would turn the project over to me, if I, in > good faith, provided sufficient evidence that I was not going to just > "sit on this project". > > In the interest of everyone understanding "my stake" in this project... > > I have the intention of building this software into the heart of an > eCommerce solution that I am working on, which should ensure the > longevity of AllCommerce, into perpetuity, even if under a new name. I > studied other components for placement in my needs matrix, but they > would all have needed too much customization and the development of > add-ins. Although it is my intention to customize the software for our > internal use at myWOL.COM and Access-Coop.Com, I believe that > AllCommerce already HAS a place in the marketplace, and simply needs a > new breath of life, and a fresh vision. > > I will borrow a saying from a favorite comedian for this disclaimer, > "That's just my opinion, I could be wrong." > > What I need to know is who can I rely on to keep this project moving > forward through the months and years. > and > Does anyone have a demonstrated need for AllCommerce, and if so then we > need your feedback, that includes everyone with a valid and considered > opinion about the growth and further development of this project's > software, AllCommerce. > > Please post your responses to the newsgroups, not to me directly. > Remember, I trying to prove that there is a job for me to do here as > Admin and Project Manager. > Barry > aka GldnEagl > -- > Sincerely, > > Barry W. Black, iEngineer > aka Golden Eagle > 916-428-3242 > gld...@ac... > > "Quite possibly... > the most Certified IT Professional in the World" > http://www.access-coop.com/bwblack/index.htm > > Owner, General Manager > iEngineer, Webmaster > Golden Eagle Enterprises > Access-coop.com - my World Online > _________________________________________ > * see my web profile, now on 144, > > with 127 from BrainBench.com... > including 10 Master Certifications, all 12 BCIP's and... > #1 Master Certified World-wide in Fiber Optics > @ http://www.brainbench.com > > 3 time Microsoft Certified Professional > http://www.microsoft.com > CompTIA A+, iNet+, Network+ > http://www.comptia.com > Certified Internet Webmaster Associate > http://www.prosoft.com > Nine certifications from SkillDrill > http://www.skilldrill.com > ================================= > > > > > > ------------------------------------------------------- > Sponsored by: AMD - Your access to the experts on Hammer Technology! > Open Source & Linux Developers, register now for the AMD Developer > Symposium. Code: EX8664 http://www.developwithamd.com/developerlab > _______________________________________________ > Allcommerce-newbies mailing list > All...@li... > https://lists.sourceforge.net/lists/listinfo/allcommerce-newbies > -- __________________________________________________________ Sign-up for your own FREE Personalized E-mail at Mail.com http://www.mail.com/?sr=signup |
|
From: Valerie & J. M. <tra...@tr...> - 2002-09-17 13:41:33
|
When it looked to me like development on this project had halted I started looking into Oscommerce, the PHP project. I'd be interested in an idea of what the goals of AllCommerce are, and how it will be different from other ecommerce packages. One item that I think would be great would be front end flexibility - as it stands it's not easy to make Oscommerce really look different. If just about everything was broken down into variables and were configurable through an admin section it would be great. Josh Barry wrote: >I'm the new guy on the team. > >I joined in response to lee heron's posting for someone to take over the >project and find the means to keep it alive, as admin and Project Lead. >I have been requested to poll the responses that I receive from this >post in order to determine a direction to take the project. First let me >say that "I believe in this product" or I wouldn't be jumping onto an >otherwise sunken ship. I dare say that all who have successfully >implemented AllCommerce, believe in it too. > >But all of that to say this... > >I need a consensus of opinion of this project from those who are still >interested in being involved with it's further development, directly, >not just standing by if you get my meaning. > >Then I need to have all who are on this team post their skills profile >and make it publicly available, so I can get a feel for who can do what. > >I also have adapted a version of the last download version of >AllCommerce to RedHat Linux 7.3 and when I am satisfied that I have >tested it sufficiently, I will make it available for download as "beta" >and with a new name if we have to, just to get it back into the public >eye. > >Lee Heron advised me that he would turn the project over to me, if I, in >good faith, provided sufficient evidence that I was not going to just >"sit on this project". > >In the interest of everyone understanding "my stake" in this project... > >I have the intention of building this software into the heart of an >eCommerce solution that I am working on, which should ensure the >longevity of AllCommerce, into perpetuity, even if under a new name. I >studied other components for placement in my needs matrix, but they >would all have needed too much customization and the development of >add-ins. Although it is my intention to customize the software for our >internal use at myWOL.COM and Access-Coop.Com, I believe that >AllCommerce already HAS a place in the marketplace, and simply needs a >new breath of life, and a fresh vision. > >I will borrow a saying from a favorite comedian for this disclaimer, >"That's just my opinion, I could be wrong." > >What I need to know is who can I rely on to keep this project moving >forward through the months and years. >and >Does anyone have a demonstrated need for AllCommerce, and if so then we >need your feedback, that includes everyone with a valid and considered >opinion about the growth and further development of this project's >software, AllCommerce. > >Please post your responses to the newsgroups, not to me directly. >Remember, I trying to prove that there is a job for me to do here as >Admin and Project Manager. >Barry >aka GldnEagl >-- >Sincerely, > >Barry W. Black, iEngineer >aka Golden Eagle >916-428-3242 >gld...@ac... > >"Quite possibly... >the most Certified IT Professional in the World" > http://www.access-coop.com/bwblack/index.htm > >Owner, General Manager >iEngineer, Webmaster >Golden Eagle Enterprises >Access-coop.com - my World Online >_________________________________________ >* see my web profile, now on 144, > >with 127 from BrainBench.com... >including 10 Master Certifications, all 12 BCIP's and... >#1 Master Certified World-wide in Fiber Optics >@ http://www.brainbench.com > >3 time Microsoft Certified Professional >http://www.microsoft.com >CompTIA A+, iNet+, Network+ >http://www.comptia.com >Certified Internet Webmaster Associate >http://www.prosoft.com >Nine certifications from SkillDrill >http://www.skilldrill.com >================================= > > > > > >------------------------------------------------------- >Sponsored by: AMD - Your access to the experts on Hammer Technology! >Open Source & Linux Developers, register now for the AMD Developer >Symposium. Code: EX8664 http://www.developwithamd.com/developerlab >_______________________________________________ >Allcommerce-newbies mailing list >All...@li... >https://lists.sourceforge.net/lists/listinfo/allcommerce-newbies > > > |
|
From: Barry <gld...@ac...> - 2002-09-17 10:59:20
|
I'm the new guy on the team. I joined in response to lee heron's posting for someone to take over the project and find the means to keep it alive, as admin and Project Lead. I have been requested to poll the responses that I receive from this post in order to determine a direction to take the project. First let me say that "I believe in this product" or I wouldn't be jumping onto an otherwise sunken ship. I dare say that all who have successfully implemented AllCommerce, believe in it too. But all of that to say this... I need a consensus of opinion of this project from those who are still interested in being involved with it's further development, directly, not just standing by if you get my meaning. Then I need to have all who are on this team post their skills profile and make it publicly available, so I can get a feel for who can do what. I also have adapted a version of the last download version of AllCommerce to RedHat Linux 7.3 and when I am satisfied that I have tested it sufficiently, I will make it available for download as "beta" and with a new name if we have to, just to get it back into the public eye. Lee Heron advised me that he would turn the project over to me, if I, in good faith, provided sufficient evidence that I was not going to just "sit on this project". In the interest of everyone understanding "my stake" in this project... I have the intention of building this software into the heart of an eCommerce solution that I am working on, which should ensure the longevity of AllCommerce, into perpetuity, even if under a new name. I studied other components for placement in my needs matrix, but they would all have needed too much customization and the development of add-ins. Although it is my intention to customize the software for our internal use at myWOL.COM and Access-Coop.Com, I believe that AllCommerce already HAS a place in the marketplace, and simply needs a new breath of life, and a fresh vision. I will borrow a saying from a favorite comedian for this disclaimer, "That's just my opinion, I could be wrong." What I need to know is who can I rely on to keep this project moving forward through the months and years. and Does anyone have a demonstrated need for AllCommerce, and if so then we need your feedback, that includes everyone with a valid and considered opinion about the growth and further development of this project's software, AllCommerce. Please post your responses to the newsgroups, not to me directly. Remember, I trying to prove that there is a job for me to do here as Admin and Project Manager. Barry aka GldnEagl -- Sincerely, Barry W. Black, iEngineer aka Golden Eagle 916-428-3242 gld...@ac... "Quite possibly... the most Certified IT Professional in the World" http://www.access-coop.com/bwblack/index.htm Owner, General Manager iEngineer, Webmaster Golden Eagle Enterprises Access-coop.com - my World Online _________________________________________ * see my web profile, now on 144, with 127 from BrainBench.com... including 10 Master Certifications, all 12 BCIP's and... #1 Master Certified World-wide in Fiber Optics @ http://www.brainbench.com 3 time Microsoft Certified Professional http://www.microsoft.com CompTIA A+, iNet+, Network+ http://www.comptia.com Certified Internet Webmaster Associate http://www.prosoft.com Nine certifications from SkillDrill http://www.skilldrill.com ================================= |
|
From: Stephen K. <sk...@cb...> - 2002-01-24 21:34:17
|
I am running AllCommerce on Guardian Digital=92s Engarde Linux = distro. I have successfully set up an online storefront, created a brand and two products. I would like now to be able to create a login page for customers and be able to set up accounts on the site. When I login to configure my store and go to the homepage manager, the only choices are the product pages I have created. I have noticed that these pages are generated from txt files in the /home/httpd/os_allcommerce/bits/html/eng/ directory and that they say template on them. There is one txt file that is called welcome_login.txt or something. How can I create a page that references that txt file and then enable it on my homepage manager? I have read the administrators guide and the users manual but to no avail. Thanks for any help you can offer. =20 =20 Stephen Kent Director of Information Technology Coastal Business Machines, Inc. HYPERLINK "mailto:sk...@cb..."sk...@cb... HYPERLINK "http://www.cbmi.com"www.cbmi.com 1-888-2FIX-UPS =20 =20 --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.314 / Virus Database: 175 - Release Date: 1/11/2002 =20 |
|
From: Karsten M. S. <km...@ix...> - 2002-01-02 23:59:48
|
on Wed, Jan 02, 2002 at 09:40:44AM -0500, Jon August (jo...@in...)= wrote: >=20 > Interchange is pretty decent. Maybe most people switched to that. >=20 > http://ic.redhat.com/ I've contacted Rob Ferber a few times to see if he's interested in picking up development. Response has been noncomittal. If Rob's listening and wants to comment, he's welcome to. I'm reviewing my own list subscriptions and am going to sign off myself in the near future. Peace. --=20 Karsten M. Self <km...@ix...> http://kmself.home.netcom.com/ What part of "Gestalt" don't you understand? Home of the brave http://gestalt-system.sourceforge.net/ Land of the free We freed Dmitry! Boycott Adobe! Repeal the DMCA! http://www.freesklyarov.org Geek for Hire http://kmself.home.netcom.com/resume.html |
|
From: Jon A. <jo...@in...> - 2002-01-02 14:40:55
|
Interchange is pretty decent. Maybe most people switched to that. http://ic.redhat.com/ On Wed, 2 Jan 2002, Mark Irving wrote: > Pretty much dead as this is the first message that I have gotten in a month. > > > ----- Original Message ----- > From: "N6REJ" <n6...@ca...> > To: "AllCommerce" <all...@li...> > Sent: Wednesday, January 02, 2002 7:17 AM > Subject: [Allcommerce-newbies] test > > > > is this list still active? > > > > Troy > > mailto:n6...@ca... > > |
|
From: Mark I. <mai...@mi...> - 2002-01-02 14:33:09
|
Pretty much dead as this is the first message that I have gotten in a month. ----- Original Message ----- From: "N6REJ" <n6...@ca...> To: "AllCommerce" <all...@li...> Sent: Wednesday, January 02, 2002 7:17 AM Subject: [Allcommerce-newbies] test > is this list still active? > > Troy > mailto:n6...@ca... > > > _______________________________________________ > Allcommerce-newbies mailing list > All...@li... > https://lists.sourceforge.net/lists/listinfo/allcommerce-newbies > |
|
From: N6REJ <n6...@ca...> - 2002-01-02 13:17:39
|
is this list still active? Troy mailto:n6...@ca... |
|
From: peter m. <kij...@ya...> - 2001-12-10 20:58:59
|
I am trying to install ALL Commerce on win2K, I have CYGwin installed and I have all commerce in the D:\cygwin\home\httpd\os_allcommerce folder, which under cygwin sould map to /home/httpd/os_allcommerce. Right ?? When I run configure.pl, I get the following error: Sitepm.Dir file not found - Program HALTED I read FAQ install and made sure that the ./conf/path.pm had the correct path... which it did coz it is the default path. when I Run setpmdir.pl I get the following errors: Error finding directory: /home/httpd/os_allcommerce/cgi-bin/om Error finding directory: /home/httpd/os_allcommerce/cgi-bin/om/admin The funny thing is that I have these folders in these locations. I am at a loss. __________________________________________________ Do You Yahoo!? Send your FREE holiday greetings online! http://greetings.yahoo.com |
|
From: Chad L. -- Shire.N. L. <ch...@sh...> - 2001-11-20 00:02:12
|
hi I installed the 1.2.3 latest on a freebsd machine with Postgresql. I am not using Apache but have a Roxen web server set up with the proper root and cgi directories etc. I run the login cgi http://server/cgi-bin/om/admin/login.cgi and I get the login screen. I type in the admin user and password and I get a 404 not found for the following URL: http://megumi-int/cgi-bin/om/admin/cgi-bin/test/login.cgi Looking at the HTML source of the login page that came up I see that the action is not "rooted" at the http root of "/" but is a relative URL. Why is this? How can I get out of test mode? Thanks Chad |
|
From: Walter H. H. <wa...@me...> - 2001-09-19 01:31:46
|
We are currently running the former OpenSales package, V0.76 and it's worked quite well for us. We need to upgrade, but I'm not considering that at this time (not for a little while -- 6 months or so in the future). The store is at http://www.thebookshop.com Walter H. Hopgood, webmaster TheBookShop.com -----Original Message----- From: all...@li... [mailto:all...@li...]On Behalf Of ken...@ba... Sent: Tuesday, September 18, 2001 9:00 AM To: all...@li... Subject: [Allcommerce-newbies] Sites Using Allcommerce? Can anyone provide links to any sites running Allcommerce? I would like to find some example sites to compare with Interchange. Thanks Kenneth _______________________________________________ Allcommerce-newbies mailing list All...@li... https://lists.sourceforge.net/lists/listinfo/allcommerce-newbies |
|
From: <ken...@ba...> - 2001-09-18 16:01:32
|
Can anyone provide links to any sites running Allcommerce? I would like to find some example sites to compare with Interchange. Thanks Kenneth |
|
From: Paul R. <pr...@cm...> - 2001-09-18 13:45:24
|
I have a site under development - http://mybabyshower.merseine.nu . We are not part of the core development group. We had to extensively rework the code to provide a gift registry function. That's the beauty of open source. If you know Perl well, you should be able to get AllCommerce to do what you need. --Paul Rinear -----Original Message----- From: all...@li... [mailto:all...@li...]On Behalf Of Josh & Valerie McCormack Sent: Tuesday, September 18, 2001 9:18 AM To: all...@li... Subject: [Allcommerce-newbies] newbie questions Hi all, I just subscribed after looking around for different opensource ecommerce software options. Allcommerce looks great, lots of features and capabilities, looks like it's been ported all over the place - different RDBMS, OS, countries needs, etc. Are there some examples of sites using it I could see? Who's using it? How's the development going? How many active developers are there? And if this looks like the system for me, where can I help (I know Perl, SQL, Flash, graphics, HTML, etc)? Thanks! Josh _______________________________________________ Allcommerce-newbies mailing list All...@li... https://lists.sourceforge.net/lists/listinfo/allcommerce-newbies |
|
From: Josh & V. M. <tra...@tr...> - 2001-09-18 13:18:27
|
Hi all, I just subscribed after looking around for different opensource ecommerce software options. Allcommerce looks great, lots of features and capabilities, looks like it's been ported all over the place - different RDBMS, OS, countries needs, etc. Are there some examples of sites using it I could see? Who's using it? How's the development going? How many active developers are there? And if this looks like the system for me, where can I help (I know Perl, SQL, Flash, graphics, HTML, etc)? Thanks! Josh |
|
From: Bob P. <sco...@ho...> - 2001-09-05 00:23:03
|
I was interested in testing out AllCommerce so I installed it on my Redhat 7.1 box in my office. I seemed to get through the install OK, and can access the manager program and login. I was able to successfully creaqte a brand, but when I go to add a product I can't. As I am filling out the product screen, no brand shows up in the drop down, the only choice is not specified. Any suggestions? Scooch _________________________________________________________________ Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp |
|
From: Bill C. <Bi...@Ex...> - 2001-09-04 03:27:03
|
The operation not permitted means you dont have the rights to make the
changes.
The \015 is a problem with the transfer. FTP the file down as binary and
upload it as ascii - that should fix it...
-----Original Message-----
From: all...@li...
[mailto:all...@li...]On Behalf Of Jalin
Arimond
Sent: Monday, September 03, 2001 7:28 PM
To: all...@li...
Subject: [Allcommerce-newbies] need help
I need help
I type ./configure.pl
And i get this
chown: /www/projectride/os_allcommerce/cgi-bin/om/Sitepm.Dir: Operation
not permit
ted
chown: /www/projectride/os_allcommerce/cgi-bin/om/admin/Sitepm.Dir:
Operation not
permitted
chown: /www/projectride/os_allcommerce/cgi-bin/om/ssl/Sitepm.Dir:
Operation not pe
rmitted
chown: /www/projectride/os_allcommerce/crons/Sitepm.Dir: Operation not
permitted
chown: /www/projectride/os_allcommerce/tools/Sitepm.Dir: Operation not
permitted
chown: /www/projectride/os_allcommerce/Sitepm.Dir: Operation not
permitted
Illegal character \015 (carriage return) at
./lib/import_shipping_tables.pm line 2
0.
(Maybe you didn't strip carriage returns after a network transfer?)
Please help
|
|
From: Jalin A. <ja...@ki...> - 2001-09-03 23:36:48
|
I need help I type ./configure.pl And i get this chown: /www/projectride/os_allcommerce/cgi-bin/om/Sitepm.Dir: = Operation not permit ted chown: /www/projectride/os_allcommerce/cgi-bin/om/admin/Sitepm.Dir: = Operation not permitted chown: /www/projectride/os_allcommerce/cgi-bin/om/ssl/Sitepm.Dir: = Operation not pe rmitted chown: /www/projectride/os_allcommerce/crons/Sitepm.Dir: Operation not = permitted chown: /www/projectride/os_allcommerce/tools/Sitepm.Dir: Operation not = permitted chown: /www/projectride/os_allcommerce/Sitepm.Dir: Operation not = permitted Illegal character \015 (carriage return) at = ./lib/import_shipping_tables.pm line 2 0. (Maybe you didn't strip carriage returns after a network transfer?) Please help |
|
From: Shawn P. B. <sp...@ho...> - 2001-08-15 23:31:20
|
I have never seen that problem. I just tried to reproduce this on my own system. I wasn't able to do it. I don't remember ever coming across this bug. My version of allcommerce is so modified I wouldn't say that there is not a bug in your existing allcommerce. Best thing to do is to look at the logs and see what you can find out from there. You may have a database problem. Kind regards, Shawn Pringle On August 15, 2001 05:33 am, Alex V. Ustinov wrote: > Problem with authentification of users ! > Operating system - Windows 2000 pro > Apache 1.3.20 + mod_ssl + openssl + ActivePerl. > > A problem in welcome.cgi unit, when do operation with e-mail address and > password of existing and new users. If to enter any e-mail address and the > existing password, access for this user will be allowed!!! For example, > user di...@us... with the password 123456 was registered, if to enter any > other e-mail, for example 12...@32..., and password of the user > di...@us... you will be accepted by system!!! > One more problem arises because custid is not transferred at input e-mail > and password. The checkout > system (checkout.cgi) is always thrown out to welcome.cgi unit! > > Please help me asap. > > With best regards, > Alex. > > > > _______________________________________________ > Allcommerce-devel mailing list > All...@li... > http://lists.sourceforge.net/lists/listinfo/allcommerce-devel |
|
From: Alex V. U. <al...@ca...> - 2001-08-15 12:33:37
|
Problem with authentification of users ! Operating system - Windows 2000 pro Apache 1.3.20 + mod_ssl + openssl + ActivePerl. A problem in welcome.cgi unit, when do operation with e-mail address and password of existing and new users. If to enter any e-mail address and the existing password, access for this user will be allowed!!! For example, user di...@us... with the password 123456 was registered, if to enter any other e-mail, for example 12...@32..., and password of the user di...@us... you will be accepted by system!!! One more problem arises because custid is not transferred at input e-mail and password. The checkout system (checkout.cgi) is always thrown out to welcome.cgi unit! Please help me asap. With best regards, Alex. |
|
From: Noel C. <NO...@mi...> - 2001-08-14 14:32:11
|
When I try to checkout, I get a DNS error. looking through checkout.cgi it seems that if there is no valid sid, I'll be forwarded to another location. Seems there are 2 problems - Anyone know why I might not be getting set an sid?, and why the redirect to inbound.cgi is giving a dns error. thanks for any help |
|
From: Noel C. <NO...@mi...> - 2001-08-13 14:45:05
|
I am trying to setup allcommerce, outside of the USA. Our Fedex shipping charges are pretty simple, determined by country to ship to and weight... that's it. Can anyone give me some pointers on what I will need to do to customise allcommerce to handle this. I've looked everywhere else for some information first, but it's thin on the ground, no archive to search and a forum that is not functioning at allcommerce.sourceforge.net (when last I checked) Thanks, Noel |
|
From: Karthik K. <ka...@ze...> - 2001-08-08 15:16:20
|
Hello- I have installed AllCommerce 1.2.3 on WinNT. Once having logged into the admin screen, I clicked on the Content Manager link. The browser hung. So, I executed admin_object.cgi, only to get the following prominent errors (apart from a lot of uninit messages: DBD::mysql::st execute failed: You have an error in your SQL syntax near '' at line 1 at d:/zennsoft/web/os_allcommerce/lib/db_layer.pm line 1169. DBD::mysql::st fetchrow_hashref feiled: fetch() withour exectue() at d:/zennsoft/web/os_allcommerce/lib/db_layer.pm line 1172. So, I printed the query to get: SELECT body FROM extraprop WHERE fieldname = 'ac_language_sens' SELECT mdate, custid, browser FROM sessions WHERE sid = Location: //login.cgi This does not seem right. Something seems awfully wrong.. why do I get two select clauses and the "Location: //login.cgi" seems fishy. Can you help me fix this, please? Thanks. Karthik Kannappan, President, ZennSoft. ka...@ze.... Phone: 510-793-5351. |
|
From: Ryan W. M. <ry...@gu...> - 2001-07-26 14:29:19
|
As the author of that advisory I'd like to comment. I have not audited
AllCommerce as of yet (I'd like to when I have the time to do so). This
particular vulnerability was a mistake on our part as we shipped the
default install in "debug mode" which dumped very insecure temp files in
/tmp.
From the advisory:
DETAIL
------
Our AllCommerce packages were released with several debugging options
enabled. This, unfortunately, leads to the creation of several
insecure files in the /tmp directory. These files have predictable
names and are thus subject to a symlink attack as the 'webd' user.
Debugging is totally disabled in this update so no files should be
created in /tmp. All users are urged to update to this latest
package.
A better fix would be to make AllCommerce use the sysopen() call which
takes C-like open flags (O_NOFOLLOW is the one of particular interest).
Just my $.02. :)
Cheers,
Ryan
+-- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --+
Ryan W. Maple "I dunno, I dream in Perl sometimes..." -LW
Guardian Digital, Inc. ry...@gu...
+-- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --+
On Wed, 25 Jul 2001, Karsten M. Self wrote:
> For those who haven't seen it, there's a locally exploitable tempfile
> vulnerability with AllCommerce. There is apparently a patch from
> EnGarde Linux:
>
> http://www.securityfocus.com/bid/3016
>
>
> bugtraq id 3016
> class Race Condition Error
> cve CVE-MAP-NOMATCH
> remote No
> local Yes
> published July 11, 2001
> updated July 12, 2001
> vulnerable Lee Herron AllCommerce 1.2.3
> Guardian Digital Engarde Secure Linux 1.0.1
>
> Is there an active patch/fix available for the SourceForge archive of
> AllCommerce?
|