THIS IS THE PR7 DOCUMENT FOR CHANGES FROM PR6 WITH module-cbamazon-3
Bugs
----
479: Second Address line at checkout
1220: Runtime >> Create Affiliate Account >> After an account is created, refreshing causes duplicate records
1912: State based sales tax not rounding correctly
4733: PayPal Pro express not sending order details
4775: Displayed numeric values not rounded (WAS: ups: Handling charge is not rounded properly)
4893: If Merchant5/sNN directory does not exist, components silently fail to update
4903: delete_store.mv: Tables that no longer exist are still deleted
4920: Launchpad buttons not assigned to a store causes a runtime error
4927: prodimpt: "Delete Existing Data When Imported Data Is Empty" deletes all custom field values
4929: Amazon Simple Pay - quotes in store name cause invalid signature
4931: Chase PaymentTech needs to be updated to include general changes we've made to all payment modules
4936: No validation of affiliate code when inserting/updating at runtime
4937: No page heading for 'Add an Affiliate' in admin
4942: Need to update PayFlow Pro XMLPayRequest URL.
4952: Sitemap component not being exported correctly when saving a framework
4953: Frameworks not implementing their contained category_tree component correctly
4954: Google Checkout needs control over the Default Shipping Method
4956: admin.mv: Miva_ValidateFileUpload returns 0 if OpenDataFiles fails
4961: Module feature changes are not propagated to stores on update
4967: Sitemap item is not exporting it's template when saving a framework
4971: External CSS files are not parsed for images when exporting a framework
4976: Chase only allows 30 characters in address field
4977: Searching "Invoice Date" searches UNIX timestamp
4988: Product export is extremely slow on MivaSQL
4992: It's possible to create a circular category hierarchy in the admin
4998: when importing products you can add products to categories even if you shoose to Keep Existing Products
4999: Product Export does not have any way to specify a delimiter
5001: Attribute template options copied to to a product cannot be sorted
5003: USPS trademark symbol should be changed from an ascii char to an entity
5004: It is possible to create an Affiliate account with no password at runtime.
5005: When custeml module is set to inactive, you cannot create a new store.
5008: There is no way to provision domain countries
5011: countries removed from Domain Settings -> Countries still show up during checkout
5056: PCHDFT item does not remove records when the product is deleted from the Batch Edit.
5057: PCHDFT item does not remove records when the category is deleted from the Batch Edit.
5059: EuroVAT Product Price Includes VAT option shouldnt calculate tax for other Basket Charges
5065: Buysafe bonding charges are being charged tax, but they should not be
5070: Flat File Customer Export has an inconsistent header field name.
5071: Flat File Product Export module doesnt have an option to specify the delimiter
5072: Import/Export Product/Category need to also support Headers & Footers
5086: Frameworks don't overwrite existing css files
5103: Category import does not allow deletion of custom field data
5104: Import Customers from Flat File does not handle custom customer fields
5111: Force secure admin login when a secure URL is configured
5126: Edit_Store variable can be used to create a store.
5127: XSS: Add/Edit Module, Module_Module unencoded
5128: XSS: Domain/LaunchPad, LaunchPadButton[n]:label/:sublabel
5129: XSS: JavaScriptEncode does not prevent against HTML comment-based attacks
5131: Domain: LaunchPad tab: Hidden error messages
5133: Upsell Batch Edit: SQL Injection on Upsell_Search
5134: Category Batch Edit Screen: XSS On Custom_Fields[n]:values
5135: Category Batch Edit Screen: XSS on Category_Search
5136: Groups has an XSS vulnerability on privilege/name fields.
5140: Edit Page: XSS on Page_Code
5141: Product Batch Edit Screen: XSS On Custom Fields variables
5142: Product Batch Edit Screen: XSS on Product_Search
5143: Customer Batch Edit: XSS on Custom_Fields[]:xxx
5144: Product Export: XSS on Product_Check_CustomFields[n]:name
5145: Customer Export: XSS on Customer_Check_CustomFields[n]:name
5146: Category Export: XSS on Category_Check_CustomFields[n]:name
5147: Custom Fields Module: Category tab outputs custom field name unencoded
5148: cmp-mv-prodctgy-meta: XSS on category component tab
5151: We need to make Runtime Login error reporting more ambiguous.
5157: USPS runtime error with zip+4 for Puerto Rico
5158: Module Batch Edit Screen: XSS on Module Feature List
5159: Edit Category >> Custom Fields >> XSS on CFM_Fields[n]:name
5160: Domain >> SEO Settings Tab >> XSS on SEO_Settings:cat_lit
5161: Customers >> Edit Customer >> Custom Fields Tab >> XSS on CFM_Fields
5162: SQL Injection in Google Checkout
5163: Google Checkout has some XSS vulnerabilities.
5164: Legacy Printer Friendly Order Screen: XSS on Edit_Store
5165: Upgrade Wizard: XSS on Upgrade_Message.
5166: License Manager URL for update.mvc goes to licensemgr.miva.com
5167: Domain >> Launchpad tab loads the module list inefficiently.
5168: Store Modules Screen: Infinite loop when g.Module_Count is not an integer
5171: Admin > SEO Settings > URL Delimiter field does not validate it's input
5173: CSSUI Buttons: XSS on store tab
5175: cmp-mv-meta: Cross Site Scripting
5176: Runtime > Edit Affiliate > Payment Date is not formatted.
5180: Utilities >> Google Checkout Orders >> The Layout appears broken.
5182: Denial of service attack through Product_Attribute_Count
5183: Denial of service attack through Upsell_Product_Count
5184: Runtime >> Affiliate Links is overwriting g.Affiliate
5185: ItemModified is not cleared on Reset/Update/Delete
5186: Upsell Settings: Validation error when products to show is "Unlimited"
5187: malf: Multiple upsold products are not logged
5193: customfields: No provisioning for category custom fields
5198: Provisoning: UI Module validation errors when creating multiple stores in the same provisioning file
5204: authnet orders do no show credit card type.
5208: PayPalPro Payment Settings Tab hides Product_Offset twice
5209: PayPalPro Product_Search is unencoded.
5210: The Next/Previous buttons fail on Products that have an ampersand in the Product Code
Bugs
----
479: Second Address line at checkout
1220: Runtime >> Create Affiliate Account >> After an account is created, refreshing causes duplicate records
1912: State based sales tax not rounding correctly
4733: PayPal Pro express not sending order details
4775: Displayed numeric values not rounded (WAS: ups: Handling charge is not rounded properly)
4893: If Merchant5/sNN directory does not exist, components silently fail to update
4903: delete_store.mv: Tables that no longer exist are still deleted
4920: Launchpad buttons not assigned to a store causes a runtime error
4927: prodimpt: "Delete Existing Data When Imported Data Is Empty" deletes all custom field values
4929: Amazon Simple Pay - quotes in store name cause invalid signature
4931: Chase PaymentTech needs to be updated to include general changes we've made to all payment modules
4936: No validation of affiliate code when inserting/updating at runtime
4937: No page heading for 'Add an Affiliate' in admin
4942: Need to update PayFlow Pro XMLPayRequest URL.
4952: Sitemap component not being exported correctly when saving a framework
4953: Frameworks not implementing their contained category_tree component correctly
4954: Google Checkout needs control over the Default Shipping Method
4956: admin.mv: Miva_ValidateFileUpload returns 0 if OpenDataFiles fails
4961: Module feature changes are not propagated to stores on update
4967: Sitemap item is not exporting it's template when saving a framework
4971: External CSS files are not parsed for images when exporting a framework
4976: Chase only allows 30 characters in address field
4977: Searching "Invoice Date" searches UNIX timestamp
4988: Product export is extremely slow on MivaSQL
4992: It's possible to create a circular category hierarchy in the admin
4998: when importing products you can add products to categories even if you shoose to Keep Existing Products
4999: Product Export does not have any way to specify a delimiter
5001: Attribute template options copied to to a product cannot be sorted
5003: USPS trademark symbol should be changed from an ascii char to an entity
5004: It is possible to create an Affiliate account with no password at runtime.
5005: When custeml module is set to inactive, you cannot create a new store.
5008: There is no way to provision domain countries
5011: countries removed from Domain Settings -> Countries still show up during checkout
5056: PCHDFT item does not remove records when the product is deleted from the Batch Edit.
5057: PCHDFT item does not remove records when the category is deleted from the Batch Edit.
5059: EuroVAT Product Price Includes VAT option shouldnt calculate tax for other Basket Charges
5065: Buysafe bonding charges are being charged tax, but they should not be
5070: Flat File Customer Export has an inconsistent header field name.
5071: Flat File Product Export module doesnt have an option to specify the delimiter
5072: Import/Export Product/Category need to also support Headers & Footers
5086: Frameworks don't overwrite existing css files
5103: Category import does not allow deletion of custom field data
5104: Import Customers from Flat File does not handle custom customer fields
5111: Force secure admin login when a secure URL is configured
5126: Edit_Store variable can be used to create a store.
5127: XSS: Add/Edit Module, Module_Module unencoded
5128: XSS: Domain/LaunchPad, LaunchPadButton[n]:label/:sublabel
5129: XSS: JavaScriptEncode does not prevent against HTML comment-based attacks
5131: Domain: LaunchPad tab: Hidden error messages
5133: Upsell Batch Edit: SQL Injection on Upsell_Search
5134: Category Batch Edit Screen: XSS On Custom_Fields[n]:values
5135: Category Batch Edit Screen: XSS on Category_Search
5136: Groups has an XSS vulnerability on privilege/name fields.
5140: Edit Page: XSS on Page_Code
5141: Product Batch Edit Screen: XSS On Custom Fields variables
5142: Product Batch Edit Screen: XSS on Product_Search
5143: Customer Batch Edit: XSS on Custom_Fields[]:xxx
5144: Product Export: XSS on Product_Check_CustomFields[n]:name
5145: Customer Export: XSS on Customer_Check_CustomFields[n]:name
5146: Category Export: XSS on Category_Check_CustomFields[n]:name
5147: Custom Fields Module: Category tab outputs custom field name unencoded
5148: cmp-mv-prodctgy-meta: XSS on category component tab
5151: We need to make Runtime Login error reporting more ambiguous.
5157: USPS runtime error with zip+4 for Puerto Rico
5158: Module Batch Edit Screen: XSS on Module Feature List
5159: Edit Category >> Custom Fields >> XSS on CFM_Fields[n]:name
5160: Domain >> SEO Settings Tab >> XSS on SEO_Settings:cat_lit
5161: Customers >> Edit Customer >> Custom Fields Tab >> XSS on CFM_Fields
5162: SQL Injection in Google Checkout
5163: Google Checkout has some XSS vulnerabilities.
5164: Legacy Printer Friendly Order Screen: XSS on Edit_Store
5165: Upgrade Wizard: XSS on Upgrade_Message.
5166: License Manager URL for update.mvc goes to licensemgr.miva.com
5167: Domain >> Launchpad tab loads the module list inefficiently.
5168: Store Modules Screen: Infinite loop when g.Module_Count is not an integer
5171: Admin > SEO Settings > URL Delimiter field does not validate it's input
5173: CSSUI Buttons: XSS on store tab
5175: cmp-mv-meta: Cross Site Scripting
5176: Runtime > Edit Affiliate > Payment Date is not formatted.
5180: Utilities >> Google Checkout Orders >> The Layout appears broken.
5182: Denial of service attack through Product_Attribute_Count
5183: Denial of service attack through Upsell_Product_Count
5184: Runtime >> Affiliate Links is overwriting g.Affiliate
5185: ItemModified is not cleared on Reset/Update/Delete
5186: Upsell Settings: Validation error when products to show is "Unlimited"
5187: malf: Multiple upsold products are not logged
5193: customfields: No provisioning for category custom fields
5198: Provisoning: UI Module validation errors when creating multiple stores in the same provisioning file
5204: authnet orders do no show credit card type.
5208: PayPalPro Payment Settings Tab hides Product_Offset twice
5209: PayPalPro Product_Search is unencoded.
5210: The Next/Previous buttons fail on Products that have an ampersand in the Product Code
Comment