<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[Blog]]></title>
    <link>https://www.magentodiy.com/blog/</link>
    <description><![CDATA[Blog]]></description>
    <pubDate>Sat, 09 May 2026 12:05:10 +0000</pubDate>
    <generator>Zend_Feed</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[常见问题]]></title>
      <link>https://www.magentodiy.com/blog/cjwt/</link>
      <description><![CDATA[<p>#1031 - Table storage engine for 'catalog_product_relation' doesn't have this option  之类&gt; MYSQL5.7默认打开。innodb_strict_mode = off in my.conf  #</p>
<p>&nbsp;</p>
<p>分树</p>]]></description>
      <pubDate>Tue, 24 Jan 2017 15:41:17 +0000</pubDate>
    </item>
    <item>
      <title><![CDATA[睿智的Magento团队 - 洛杉矶]]></title>
      <link>https://www.magentodiy.com/blog/magento-tuandui/</link>
      <description><![CDATA[<p><img title="Magento 团队" src="https://www.magentodiy.com/media/wysiwyg/magento_tuandui.jpg" alt="Magento 团队" /><br /><img src="https://www.magentodiy.com/media/wysiwyg/LA_Bugathon_1.jpg" alt="" /><img src="https://www.magentodiy.com/media/wysiwyg/Zurich_Hackathon_1.jpg" alt="" /></p>]]></description>
      <pubDate>Sat, 21 Dec 2013 16:24:08 +0000</pubDate>
    </item>
    <item>
      <title><![CDATA[祝贺MagentoDIY成为GO合作伙伴]]></title>
      <link>https://www.magentodiy.com/blog/magentogo-huoban/</link>
      <description><![CDATA[<p><span style="color: #ff6600;">祝贺MagentoDIY成为GO合作伙伴</span></p>
<p><span style="color: #ff6600;">Magento GO是在线商店，让客户从最简单的方式来运营自己的产品，随着电子商务平台的信任，超过150,000招商 。</span></p>
<p>&nbsp;<a title="Magento GO" href="http://www.pntra.com/t/SEFNSUpLRUFFRERFSktBTUZGSEU" target="_blank"><img title="Magento GO 合作伙伴" src="https://www.magentodiy.com/media/wysiwyg/magentodiy_go.png" alt="Magento GO 合作伙伴" /></a></p>
<p>&nbsp;</p>]]></description>
      <pubDate>Sat, 01 Dec 2012 14:44:21 +0000</pubDate>
    </item>
    <item>
      <title><![CDATA[Magento 2012年秋季电子商务论坛]]></title>
      <link>https://www.magentodiy.com/blog/Magento_E-Commerce_Forum_Summit_in_the_fall_of_2012_in_quarter/</link>
      <description><![CDATA[<h2 class="page-head" style="margin: 0px; padding: 0px; line-height: normal; font-size: 28px; font-weight: normal; color: #002d53; font-style: normal; font-variant: normal; font-family: arial, helvetica; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><small style="margin: 0px; padding: 0px; font-size: 0.95em;"><span><span>秋季2012年电子商务论坛峰会</span></span></small><span><span>&nbsp;</span></span></h2>
<div style="margin: 0px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18.600000381469727px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<div class="f-left a-left share-buttons" style="margin: 0px 0px 8px; padding: 0px; text-align: left; float: left;"><span class="st_twitter_hcount" style="margin: 0px; padding: 0px; display: block; float: left;"><span class="stButton" style="margin: 0px 3px; padding: 0px; position: relative; z-index: 1; text-decoration: initial; color: #000000; display: inline-block; cursor: pointer; font-size: 11px; line-height: 16px; float: left;"><span style="margin: 0px; padding: 0px; display: block; float: left;"><span class="stMainServices st-twitter-counter" style="margin: 0px; padding: 3px 0px; display: inline-block; float: left; background-image: url(http://w.sharethis.com/images/twitter_counter.png); white-space: nowrap; font-family: Verdana, Helvetica, sans-serif; font-size: 11px; height: 16px; line-height: 16px; width: 60px; position: relative; background-repeat: no-repeat no-repeat;">&nbsp;</span></span></span></span></div>
</div>
<div class="entry" style="margin: 0px; padding: 17px 0px 7px; clear: both; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18.600000381469727px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><img style="margin: 0px; padding: 0px 0px 15px; border: 0px;" title="Magento 2012 秋季电商论坛" src="https://www.magentodiy.com/media/wysiwyg/Magentoe_Comm_Forum.jpg" alt="Magento 2012 秋季电商论坛" width="670" height="116" />
<p style="margin: 0px 0px 10px; padding: 0px;"><span><span>Magento电子商务论坛给零售商和厂家的机会，以满足电子商务需求从我们的产业链系统，</span><span>与会者们交流，更多的了解我们的解决方案，工业和托管合作伙伴携手共进，实现成功的Magento网站的零售商增加销售和客户忠诚度的结果。</span><span>这些论坛也是一个机会，为商户提供有价值的电子商务技巧，采取​​和实施自己的企业。</span></span></p>
<p style="margin: 0px 0px 10px; padding: 0px;"><span><span>今年秋天，我们有机会在16个城市，以满足零售商从多伦多到纽约，洛杉矶，迈阿密，和许多城市之间。</span><span>随着电子商务的持续增长和发展，我们将继续举办这些活动，使我们能够分享电子商务的知识，最佳做法和成功的Magento客户的故事。</span><span>随着电子商务的持续增长和发展，我们将继续与Magento的社区分享，成功经验和最佳做法，通过这些论坛。</span></span></p>
<p style="margin: 0px 0px 10px; padding: 0px;"><span><span>我们非常感谢我们的合作伙伴提供的宝贵支持，使这些事件可能。</span><span>非常感谢所有的合作伙伴，赞助跌倒事件。</span></span></p>
<p style="margin: 0px 0px 10px; padding: 0px;"><img style="margin: 0px; padding: 10px 0px; border: 0px;" title="MagentoDIy.Com" src="https://www.magentodiy.com/media/wysiwyg/2012_Magento_eCommForum_Sign_Sponsors.jpg" alt="MagentoDIy.Com" width="669" height="322" /></p>
<p style="margin: 0px 0px 10px; padding: 0px;"><span><span>最后，谢谢大家，我们的Magento所有参加我们的电子商务活动的伙伴。</span><span>您的精力，热情和创造力，是鼓舞人心的。</span></span></p>
</div>]]></description>
      <pubDate>Fri, 09 Nov 2012 02:59:27 +0000</pubDate>
    </item>
    <item>
      <title><![CDATA[Magento RPC-Zend框架的漏洞安全更新]]></title>
      <link>https://www.magentodiy.com/blog/magento-rpc/</link>
      <description><![CDATA[<p>Magento RPC漏洞解决方案：</p>
<p>基于 Zend 的安全漏洞，可直接读取服务器任何信息。各位客户可根据自己的Magento版本,SVN相应补丁，或注释掉以下文件的代码即可。（本司客户，请发站内支援请求，并提供FTP，会有程序员帮您打上补丁的。）</p>
<p><strong>解决方案 / Solution</strong></p>
<h3 style="margin: 10px 0px 5px; padding: 0px; line-height: 22px; color: #444444; font-size: 17px; font-weight: bold; font-style: normal; font-variant: normal; font-family: Arial; text-transform: none; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><span><span>Magento企业版</span></span></h3>
<hr style="margin: 15px 0px; padding: 0px; clear: both; border: 1px; height: 1px; overflow: hidden; visibility: visible; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #cccccc;" />
<ul style="margin: 0px 0px 12px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;"><span><span>根据我们实践总结，我们建议，所有的企业版的客户，尽可能请升级到最新版本（v1.12.0.2）采取最新补丁和功能。</span></span></li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;"><span><span>或者根据您的平台版本，请选择相应的解决方案：</span></span></li>
</ul>
<table style="margin: 0px 0px 0px 20px; padding: 0px; width: 670px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<tbody style="margin: 0px; padding: 0px;">
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><strong style="margin: 0px; padding: 0px;"><span><span>您的当前版本</span></span></strong></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><strong style="margin: 0px; padding: 0px;"><span><span>推荐的解决方案</span></span></strong></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento 企业版 1.12.0.0 +</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: none;" title="升级到最新版本 " href="https://www.magentocommerce.com/products/customer/account/index/"><span><span>升级到最新版本</span></span></a><span><span>（浏览下载Magento企业版&gt;发布-登录帐户的要求）</span></span></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento 企业版 1.8.0.0 - 1.11.XX</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: none;" title="申请的Zend安全升级补丁" href="https://www.magentocommerce.com/products/customer/account/index/"><span><span>应用在Zend的安全升级补丁</span></span></a><span><span>（浏览下载Magento企业版&gt;补丁与支持-登录帐户是必需）</span></span></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento 企业版本1.8.0.0之前的版本</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><span><span>可使用变通办法（以下说明）</span></span></td>
</tr>
</tbody>
</table>
<p><br style="margin: 0px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;" /></p>
<h3 style="margin: 10px 0px 5px; padding: 0px; line-height: 22px; color: #444444; font-size: 17px; font-weight: bold; font-style: normal; font-variant: normal; font-family: Arial; text-transform: none; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><span><span>Magento的专业版</span></span></h3>
<hr style="margin: 15px 0px; padding: 0px; clear: both; border: 1px; height: 1px; overflow: hidden; visibility: visible; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #cccccc;" />
<ul style="margin: 0px 0px 12px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;"><span><span>专业版的所有版本，请申请</span></span><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: none;" title="Zend的安全升级补丁 " href="https://www.magentocommerce.com/products/customer/account/index/"><span><span>的Zend安全升级补丁</span></span></a><span><span>（浏览下载Magento的专业版，需要登录帐户）</span></span></li>
</ul>
<p><br style="margin: 0px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;" /></p>
<h3 style="margin: 10px 0px 5px; padding: 0px; line-height: 22px; color: #444444; font-size: 17px; font-weight: bold; font-style: normal; font-variant: normal; font-family: Arial; text-transform: none; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><span><span>Magento的社区版</span></span></h3>
<hr style="margin: 15px 0px; padding: 0px; clear: both; border: 1px; height: 1px; overflow: hidden; visibility: visible; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #cccccc;" />
<ul style="margin: 0px 0px 12px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;"><span><span>如果可以，我们建议，所有社区版客户尽量升级到最新版本（v1.7.0.2），使用最新的补丁和功能优势。</span></span></li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;"><span><span>若不方便升级，可根据您的平台版本，请找到相应的解决方案：</span></span></li>
</ul>
<table style="margin: 0px 0px 0px 20px; padding: 0px; width: 670px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<tbody style="margin: 0px; padding: 0px;">
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><strong style="margin: 0px; padding: 0px;"><span><span>您的当前版本</span></span></strong></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><strong style="margin: 0px; padding: 0px;"><span><span>推荐的解决方案</span></span></strong></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento1.7.0.0 +</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: none;" title="升级到最新版本 " href="http://www.magentocommerce.com/download"><span><span>升级到最新版本</span></span></a></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento1.5.0.0 至 1.6.XX</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: none;" title="应用此修补程序" href="http://www.magentocommerce.com/downloads/assets/1.7.0.2/CE_1.5.0.0-1.7.0.1.patch"><span><span>应用此修补程序</span></span></a></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento1.4.2.0</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: none;" title="应用此修补程序" href="http://www.magentocommerce.com/downloads/assets/1.7.0.2/CE_1.4.2.0.patch"><span><span>应用此修补程序</span></span></a></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento1.4.0.0 至1.4.1.1</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: none;" title="应用此修补程序" href="http://www.magentocommerce.com/downloads/assets/1.7.0.2/CE_1.4.0.0-1.4.1.1.patch"><span><span>应用此修补程序</span></span></a></td>
</tr>
<tr style="margin: 0px; padding: 0px;">
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="200px"><span><span>Magento1.4.0.0以前的版本</span></span></td>
<td style="margin: 0px; padding: 0px; vertical-align: top;" width="400px"><span><span>可使用变通办法（以下说明）</span></span></td>
</tr>
</tbody>
</table>
<p><br style="margin: 0px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;" /></p>
<h3 style="margin: 10px 0px 5px; padding: 0px; line-height: 22px; color: #444444; font-size: 17px; font-weight: bold; font-style: normal; font-variant: normal; font-family: Arial; text-transform: none; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><span><span>Magento GO</span></span></h3>
<hr style="margin: 15px 0px; padding: 0px; clear: both; border: 1px; height: 1px; overflow: hidden; visibility: visible; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #cccccc;" />
<p style="margin: 0px 0px 10px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><span><span>Magento GO的客户将不需要做任何更新。</span><span>所有修补程序将在后台自动应用。</span></span></p>
<h4 style="margin: 0px 0px 0.2em; padding: 0px; line-height: 1.3em; font-size: 1.25em; color: #222222; font-family: Arial, sans-serif; font-style: normal; font-variant: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">Instructions on Applying the Patch</h4>
<ul style="margin: 0px 0px 12px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">1.	Go to the root of your Magento root directory: cd /home/mystore/public_html</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">2.	wget &ndash;O patch_name.patch</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">3.	Download the patch from the provided link appropriate for your version (this line allows you to do it from the Unix command prompt)</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">4.	Apply the patch: patch -p0 &lt; patch_name.patch</li>
</ul>
<p style="margin: 0px 0px 10px 20px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><em style="margin: 0px; padding: 0px;">*Note that if you are running more than one web server, the patch will need to be applied to all the servers.</em></p>
<h4 style="margin: 0px 0px 0.2em; padding: 0px; line-height: 1.3em; font-size: 1.25em; color: #222222; font-family: Arial, sans-serif; font-style: normal; font-variant: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">Workaround</h4>
<p style="margin: 0px 0px 10px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">If an upgrade cannot be performed or the patch cannot be applied immediately, the following instructions can be followed to temporarily disable the RPC functionality that contains the vulnerability.</p>
<p style="margin: 0px 0px 10px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">Please note that this workaround can only be applied to versions of CE 1.4 and below and EE 1.8 and below.</p>
<p style="margin: 0px 0px 10px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">Also, please be advised that any integrations that rely on the XMLRPC API functionality will no longer work after this workaround is implemented.</p>
<ul style="margin: 0px 0px 12px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">1. On the Magento web server, navigate to the www-root where Magento app files are stored.</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">2. In the wwwroot, navigate to /app/code/core/Mage/Api/controllers.</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">3. Open XmlrpcController.php for editing.</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">4. Comment out or delete the body of the method: public indexAction()</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">5. Save the changes.</li>
</ul>
<h4 style="margin: 0px 0px 0.2em; padding: 0px; line-height: 1.3em; font-size: 1.25em; color: #222222; font-family: Arial, sans-serif; font-style: normal; font-variant: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">Technical Clarification</h4>
<p style="margin: 0px 0px 10px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">As some of our experienced community members have discovered, the development fix in CE 1.7.0.2 and EE 1.12.0.2 differ from the fix provided in the patches. In the latest releases, we decided not modify the Zend library directly, but override vulnerable methods within Magento Code by adding two new classes:</p>
<ul style="margin: 0px 0px 12px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">app/code/core/Zend/XmlRpc/Response.php</li>
<li style="margin: 0px 0px 0px 20px; padding: 0px; list-style: none;">app/code/core/Zend/XmlRpc/Request.php</li>
</ul>
<p style="margin: 0px 0px 10px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">We did this in order to keep coherency of the underlying Zend Framework version 1.11.1 for Magento 1.X. We are planning to upgrade the Zend Framework in Magento in the upcoming releases.</p>]]></description>
      <pubDate>Thu, 05 Jul 2012 00:38:00 +0000</pubDate>
    </item>
    <item>
      <title><![CDATA[Magento EE企业版缓存攻击]]></title>
      <link>https://www.magentodiy.com/blog/magento-ee-Cache-Poisoning-Attac/</link>
      <description><![CDATA[<pre style="margin: 0em;">Summary:

Magento Enterprise Edition is vulnerable to poisoning of its page cache
under some configurations due to inappropriate trust of HTTP Host header
values.


Impact:

Users shopping at online stores driven by Magento EE can be redirected
to arbitrary third party sites, allowing malicious entities to entice
users to hand over their credit card information inappropriately.


Severity:

Major -- Exploit allows for content injection, and hijacking of users.
Exploits have been observed in the wild.


Fix/Workaround Status:

At this time, the vendor (Magento Inc) has only stated an intent to fix
the problem (as a "product enhancement") but has not provided any patch
despite being given considerable lead time by us and being first made
aware of the problem in 2008 (see note below for more details).

The issue can be worked around using one of several configuration-
related changes, including one which the vendor introduced in 2008.


Affected Versions:

All versions of Magento EE, up to and including 1.9.1.1 (the latest as
of this writing) when page caching is enabled.  It is unclear if the
block-level caching in Magento Community/Professional Edition is
similarly impacted, however both are likely vulnerable to the
misinterpretation of data.


Details:

Magento uses a hierarchical configuration mechanism, allowing values
such as site URLs to be set at a global level and at a more specific
per-storefront level.  Magento EE adds a mechanism for caching whole
pages.

With default URL values, Magento EE can be tricked into generating page
cache entries with arbitrary URL values by simply sending an artificial
HTTP Host header.  Unfortunately, setting the URL value at the
*storefront* level is insufficient to prevent this behavior.

In order to prevent this issue, one of the following must be true:

The key is to have the web server send only trustworthy/cleansed values
to PHP.

The following are example approaches for Apache:

* Your web server is configured in a way that results in untrusted Host
values never being sent to PHP.  An example of this would be the use of
name-based vhosts that do not point the "_default_" vhost to a Magento
instance.

* Using one or more ServerAlias masks with IP-based vhosting to
constrain the range of valid host values.

Magento level:

* Provide Base Unsecure URL and Base Secure URL values in the "Default
Config" (top-level) configuration.  The precise values do not appear to
matter, just so long as some value is present.

Reproducing the problem simply requires requesting any URL with a forged
Host header at a time when the page cache is considered invalid.


Nota Bene:

The vendor's solution to the problem when confronted with it in 2008[1]
was to introduce a vaguely worded warning[2] in the admin UI when the
base URL value is not defined at the top level of the configuration
hierarchy.

Given that:

1) It is not made clear that the configuration status presents a severe
security hole.

2) A non-default base URL value in the top-level configuration level is
never actually *used* in page-cache generation.  Its presence apparently
serves only to trigger use of the per-storefront configuration value.

We therefore hold that the provided warning does not suffice as a 'fix'.
The vendor has indicated that they believe otherwise both through their
actions and their communications with us.


References:

[1] <a rel="nofollow" href="http://www.magentocommerce.com/boards/viewthread/8220/">http://www.magentocommerce.com/boards/viewthread/8220/</a>

[2] The exact wording of the message is:  "{{base_url}} is not
recommended to use in a production environment to declare the Base
Unsecure URL / Base Secure URL. It is highly recommended to change this
value in your Magento configuration."</pre>]]></description>
      <pubDate>Mon, 07 Feb 2011 04:20:00 +0000</pubDate>
    </item>
    <item>
      <title><![CDATA[Magento 系统要求]]></title>
      <link>https://www.magentodiy.com/blog/System_Requirements/</link>
      <description><![CDATA[<h2 class="page-head" style="margin: 0px 0px 16px; padding: 0px; line-height: normal; font-size: 28px; font-weight: normal; color: #002d53; font-style: normal; font-variant: normal; font-family: arial, helvetica; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">System Requirements</h2>
<h4 class="light-grey-head" style="margin: 0px 0px 13px; padding: 2px 10px; line-height: 1.3em; font-size: 12px; color: #333333; background-color: #ebebeb; font-family: Arial, sans-serif; font-style: normal; font-variant: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-position: initial initial; background-repeat: initial initial;">At the base level, Magento will require the following software:</h4>
<p style="margin: 0px 0px 10px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18.600000381469727px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;"><a style="margin: 0px; padding: 0px; color: #0068b7; text-decoration: initial;" href="http://www.magentodiy.com/media/public_download/magento-check.zip">1:环境检测器 &nbsp;Magento environment detector</a><br /><a href="http://www.magentodiy.com/media/public_download/magento-cleanup.zip">2:权限重置&nbsp;Magento permissions reset</a>&nbsp;<br /><a href="http://www.magentodiy.com/media/public_download/magento-db-repair-tool-1.1.zip">3:数据库修复 Magento database repair</a> &nbsp;<br /><br /></p>
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px; color: #555555; font-family: Arial, sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18.600000381469727px; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: #fefefe;">
<li style="margin: 0px 0px 5px; padding: 0px 0px 0px 9px; list-style: none; background-image: url(http://www.magentocommerce.com/img/disc_li_bg.gif); line-height: 1.35em; background-position: 0px 7px; background-repeat: no-repeat no-repeat;">Supported Operating Systems:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Linux x86, x86-64</li>
</ul>
</li>
<li style="margin: 0px 0px 5px; padding: 0px 0px 0px 9px; list-style: none; background-image: url(http://www.magentocommerce.com/img/disc_li_bg.gif); line-height: 1.35em; background-position: 0px 7px; background-repeat: no-repeat no-repeat;">Supported Web Servers:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Apache 1.3.x</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Apache 2.0.x</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Apache 2.2.x</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Nginx (starting from Magento 1.7 Community and 1.12 Enterprise versions)</li>
</ul>
</li>
<li style="margin: 0px 0px 5px; padding: 0px 0px 0px 9px; list-style: none; background-image: url(http://www.magentocommerce.com/img/disc_li_bg.gif); line-height: 1.35em; background-position: 0px 7px; background-repeat: no-repeat no-repeat;">Supported Browsers:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Microsoft Internet Explorer 7 and above</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Mozilla Firefox 3.5 and above</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Apple Safari 5 and above on Mac only</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Google Chrome 7 and above</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Adobe Flash browser plug-in should be installed</li>
</ul>
</li>
<li style="margin: 0px 0px 5px; padding: 0px 0px 0px 9px; list-style: none; background-image: url(http://www.magentocommerce.com/img/disc_li_bg.gif); line-height: 1.35em; background-position: 0px 7px; background-repeat: no-repeat no-repeat;">PHP Compatibility:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">5.2.13 - 5.3.15</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Required extensions:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">PDO_MySQL</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">simplexml</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">mcrypt</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">hash</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">GD</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">DOM</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">iconv</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">curl</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">SOAP (if Webservices API is to be used)</li>
</ul>
</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Safe_mode off</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Memory_limit no less than 256Mb (preferably 512)</li>
</ul>
</li>
<li style="margin: 0px 0px 5px; padding: 0px 0px 0px 9px; list-style: none; background-image: url(http://www.magentocommerce.com/img/disc_li_bg.gif); line-height: 1.35em; background-position: 0px 7px; background-repeat: no-repeat no-repeat;">MySQL:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">4.1.20 or newer</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">InnoDB storage engine</li>
</ul>
</li>
<li style="margin: 0px 0px 5px; padding: 0px 0px 0px 9px; list-style: none; background-image: url(http://www.magentocommerce.com/img/disc_li_bg.gif); line-height: 1.35em; background-position: 0px 7px; background-repeat: no-repeat no-repeat;">SSL:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">If HTTPS is used to work in the admin, SSL certificate should be valid. Self-signed SSL certificates are not supported</li>
</ul>
</li>
<li style="margin: 0px 0px 5px; padding: 0px 0px 0px 9px; list-style: none; background-image: url(http://www.magentocommerce.com/img/disc_li_bg.gif); line-height: 1.35em; background-position: 0px 7px; background-repeat: no-repeat no-repeat;">Server - hosting - setup:        
<ul class="disc" style="margin: 0px 0px 12px; padding: 0px;">
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Ability to run scheduled jobs (crontab) with PHP 5</li>
<li style="margin: 0px 0px 5px 20px; padding: 0px; list-style-type: circle; list-style-position: initial; list-style-image: initial; background-image: none; line-height: 1.35em; background-position: initial initial; background-repeat: initial initial;">Ability to override options in .htaccess files</li>
</ul>
</li>
</ul>]]></description>
      <pubDate>Tue, 17 Mar 2009 06:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
