Another OsCommerce Bug...Buy an mp3 player for everybody in the world for only $1.43

Discussion in 'PHP' started by dotcomsdotbiz, May 19, 2006.

  1. #1
    I won't tell you the site that I could be 90 billion mp3 players for a grand total of $1.43 but I am sure you can find plenty of others...

    Go to your favorite online merchant that uses OsCommerce. Enter 1 item in the cart. Then update the quanity to 9999. Then update the quanity to 99999999999999999. There you go over a billion dollars worth of merchandise for almost nothing...

    I wonder what the liabilities are if this is not addressed on their site in their terms and conditions ;)
     
    dotcomsdotbiz, May 19, 2006 IP
  2. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Mine calculates 9999 OK, 999999999999999 indeed goes back to the single unit price.

    Then again, it's not like it will go unnoticed and we will actually ship 100 billion of that product.

    Interesting though, I'll patch it soon.

    EDIT: It's only in the cart, during check-out it calculates the correct price though it cuts down to 2147483647 (MAX Integer in MySQL)

    2147483647 x PRODUCT X £94,381,906,285.65
     
    T0PS3O, May 19, 2006 IP
  3. dotcomsdotbiz

    dotcomsdotbiz Banned

    Messages:
    73
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #3
    You would think that they would set a MAX field value for the cart...

    Mike :)
     
    dotcomsdotbiz, May 19, 2006 IP
  4. Big 'G'

    Big 'G' Member

    Messages:
    89
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    48
    #4
    :D Nice find think they need some limits of the quantiy, did try one site and it calc the right price though
     
    Big 'G', May 19, 2006 IP
  5. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #5
    It being Open Source, 'they' is as much 'you' as anyone else. Feel free to report a bug with fix and all.
     
    T0PS3O, May 19, 2006 IP
  6. dotcomsdotbiz

    dotcomsdotbiz Banned

    Messages:
    73
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Some of the newer sites seem to have it fixed. Some on checkout it calculates the correct value some it lets you checkout. Maybe its related to a previous version of OsCommerce.

    :)
     
    dotcomsdotbiz, May 19, 2006 IP
  7. wvccboy

    wvccboy Notable Member

    Messages:
    2,632
    Likes Received:
    81
    Best Answers:
    1
    Trophy Points:
    250
    #7
    That'd be nice if I could buy that much; they'd have to ship it anyway... "I paid for it!"
     
    wvccboy, May 25, 2006 IP
  8. ablaye

    ablaye Well-Known Member

    Messages:
    4,024
    Likes Received:
    97
    Best Answers:
    0
    Trophy Points:
    150
    #8
    Ha ha, that's a good one. However, it would never work as any idiot would notice this mistake and not ship you the products.
     
    ablaye, May 26, 2006 IP