ProductCart E-Commerce Solutions Homepage
Forum Home Forum Home > ProductCart > Using ProductCart
  New Posts New Posts RSS Feed - Security
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Security

 Post Reply Post Reply
Author
Message
steverguy View Drop Down
Groupie
Groupie


Joined: 05-April-2006
Location: United States
Status: Offline
Points: 44
Post Options Post Options   Thanks (0) Thanks(0)   Quote steverguy Quote  Post ReplyReply Direct Link To This Post Topic: Security
    Posted: 20-May-2013 at 2:24pm
So... we get our site scanned every so often for PCI complience.  This time around we failed due to "Web Application Transmits Login Credentials Without Encryption"  regarding http://www.oursite.com/pc/checkout.asp?cmode=1.  (that's not really our domain...Big smile).
Our product cart settings are set to go secure when someone registers or logsin.  To be safe, all of my links for logging in include our full domain path, including the https://  - but, if you go to http://www.blahblah.com/pc/checkout.asp?cmode=1 directly you can login without it switching to SSL. 
 
Shouldn't this change to ssl regardless of how I navigate to the page?
"Remember, 72.5% of all statistics are made up."
Back to Top
Hamish View Drop Down
Admin Group
Admin Group


Joined: 12-October-2006
Location: United Kingdom
Status: Offline
Points: 56
Post Options Post Options   Thanks (0) Thanks(0)   Quote Hamish Quote  Post ReplyReply Direct Link To This Post Posted: 20-May-2013 at 3:12pm
Hi Setverguy, yes, we take security very seriously, please raise a support ticket so we can help  identify the issue.
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.063 seconds.