In the case I was talking about, it was even worse. The Javascript just set a GET param that said the password is OK. You can then log in as anyone with this method.
As I recall, it did send you the plaintext password too, of course.
As I recall, it did send you the plaintext password too, of course.
No comments yet.